critical Cve 2026 35273 · Exploits

ShinyHunters Exploits Oracle PeopleSoft CVE-2026-35273 via WAF Bypass

Data graphic: one percent-encoded letter, /%50SEMHUB/, gets past WAF rules that block /PSEMHUB/. The attack path runs from the POST request through the WAF, which matches the literal path, to the app server that decodes it, then the PSEMHUB servlet and a web shell or fileless commands, for CVSS 9.8 Critical CVE-2026-35273.
EV

Data security correspondent · Updated Oct 2, 2026, 3:27 PM EDT

GTIG says UNC6240 (ShinyHunters) is again exploiting PeopleSoft CVE-2026-35273, using /%50SEMHUB/ to slip past WAF rules. Patch, then hunt.

Google Threat Intelligence Group (GTIG, Mandiant) reported on 26 September 2026 that UNC6240, which it tracks as ShinyHunters, is again exploiting CVE-2026-35273 in Oracle PeopleSoft PeopleTools. GTIG describes web shells deployed on dozens of systems globally. The campaign runs months after Oracle's out-of-band fix and gets past perimeter rules with a one-character trick: percent-encoding the letter P in the request path. GTIG says the actor targeted organisations that put WAF rules in place but did not patch.

What is affected

CVE-2026-35273 is a flaw in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools. Per the CVE record, an unauthenticated attacker with HTTP access can take over the product. The record lists PeopleTools 8.61 and 8.62 as affected and carries a CVSS v3.1 base score of 9.8 (Critical), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, supplied by Oracle as the CVE Numbering Authority. CISA's ADP data in the same record classifies it as CWE-306, missing authentication for a critical function. GTIG identifies the vulnerable code as the Environment Management Hub (PSEMHUB) servlet.

The timeline, as reported by GTIG and the CVE record:

  • 27 May to 9 June 2026: zero-day exploitation, predominantly against higher education (GTIG).
  • 10 June 2026: Oracle issues an out-of-band Security Alert (GTIG).
  • 12 June 2026: CISA adds the flaw to its Known Exploited Vulnerabilities catalog. CISA's SSVC data in the CVE record rates exploitation as active, the flaw as automatable, and technical impact as total.
  • 26 September 2026: GTIG publishes its report on the renewed campaign, covering intrusions in September.

The renewed wave is broader than the original. GTIG lists higher education, technology, IT services, healthcare, agriculture, transportation and government among the targets.

The bypass

Defenders who blocked /PSEMHUB/ at a WAF or reverse proxy were not protected. The actor requests /%50SEMHUB/ instead, where %50 is the URL encoding of P. GTIG explains why it works: many WAF and reverse-proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet. GTIG tells defenders to assume the actor may use any percent-encoded, mixed-case or otherwise non-normalised variant of /PSEMHUB/, and to enforce blocking on the normalised path.

Attack chain

GTIG describes a consistent sequence. First comes verification: five to 15 POST requests to /%50SEMHUB/hub carrying a serialized Java object. Unpatched servers respond with the host operating system without writing files or disrupting the service, so the check is quiet.

Exploitation then follows one of two routes:

  1. Web shell. Further POST requests to the same endpoint drop JSP files, including x.jsp, u.jsp and sequentially numbered files, into the PSEMHUB.war directory. GTIG notes the repetition likely ensures every node behind a load balancer gets a copy. x.jsp is a cross-platform command shell that accepts hex-encoded commands via POST (c) with an optional timeout (t). u.jsp decodes Base64 file chunks and writes or appends them to a target path in 150 KB increments.
  2. Fileless. Command output returns directly in the HTTP response with no file written to disk. The only host trace is shell processes (cmd.exe or /bin/sh) spawned by the WebLogic Java process, so detections built on JSP file creation will miss it.

Follow-on tooling includes Ple64.exe, a trojanized installer that masquerades as a signed installer for the Light Alloy media player. GTIG says it runs a three-stage chain that loads the SIDEEYE C++ backdoor in memory. SIDEEYE supports browser and desktop credential theft, process and file management, and an interactive reverse shell and reverse proxy, and it talks to its command server over raw TCP. The actor also deploys the open-source Neo-reGeorg toolkit (tunnel.jsp or tunnel.jspx), which carries SOCKS5 proxy traffic over ordinary HTTP and HTTPS to the web tier, and on Linux uses the legitimate remote management tool MeshAgent for persistence. A quarter of the actor's commands ran as root or NT Authority\SYSTEM.

Indicators from GTIG (defanged)

IndicatorRole
5[.]199[.]162[.]157Attack controller, scanner, HTTP callback receiver
104[.]219[.]234[.]138Exfiltration staging, remote management
162[.]219[.]30[.]165 (TCP/3333 control, TCP/3334 data)SIDEEYE C2
winmanage-me[.]networkResolves to the staging host; MeshCentral infrastructure
x.jsp SHA-25648b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494
u.jsp SHA-2562bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7
Ple64.exe SHA-2563ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3

Web shells appear under <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/.

What defenders should do

  1. Patch. Apply the patch in Oracle's Security Alert for CVE-2026-35273. WAF rules were the stopgap this actor walked around.
  2. Reduce exposure. GTIG advises disabling the EMHub service in multi-server configurations and removing PSEMHUB entirely in single-server ones. Keep it off the internet either way.
  3. Hunt. Search PIA WebLogic access logs for /PSEMHUB/ and percent-encoded variants, especially POST requests to /hub. Inspect the PSEMHUB.war directory, including envmetadata/transactions/, for unexpected .jsp, .jspx and .exe files, and check for unexpected MeshCentral agents. Check every WebLogic node behind a load balancer, not only the first one you find. Monitor outbound traffic to the indicators above.
  4. Watch for fileless activity. Alert on shells (cmd.exe, /bin/sh, bash) spawned by the WebLogic Java process, particularly those invoking base64 -d, curl, /dev/tcp, tasklist or start /b. Review PeopleSoft and database hosts for large .tar, .tar.gz and .zst archives in temporary or web-accessible directories.
  5. Rotate credentials. Replace credentials readable by the PeopleSoft application service account: database connection strings in psappsrv.cfg, Integration Broker credentials and any cloud credentials reachable from the web tier.
  6. Plan for extortion. GTIG notes UNC6240's well-established pattern of stealing data and threatening to leak it unless the victim pays, so prepare legal and communications teams.

The lesson

A WAF rule keyed to a literal path is a virtual patch, and a virtual patch is only as good as its normalisation. The same lesson applies in the WebLogic proxy-bypass case: when the fix exists, the front-end filter is a stopgap, not the remedy.

Sources

Keep reading

All latest →
  1. highExploitsZyxel GS1900 switch overflow exploited on 996 devices, now in CISA KEV4 min
  2. highExploitsMicrosoft SharePoint CVE-2026-65660 Added to CISA KEV After Rescore to RCE5 min
  3. criticalExploitsWSO2 API Manager JWT Bypass Exploited 133 Days After the Fix5 min
  4. criticalExploitsF5 BIG-IP APM: An Oversized Bearer Token Is Enough for Unauthenticated RCE6 min
  5. highExploitsApple Patches CoreGraphics Zero-Day Used Against Targeted iPhone Users5 min
  6. highExploitsWordPress Core Flaw CVE-2026-87902 Drew Exploit Attempts on Patch Day7 min