A Patched Vulnerability Comes Back Around
Google's Threat Intelligence Group (GTIG), working with Mandiant, is warning of a renewed mass exploitation campaign targeting Oracle PeopleSoft deployments — reusing a vulnerability Oracle already patched, by simply encoding requests in a way that slips past web application firewalls (WAFs) configured to block the original attack pattern. The activity is linked to ShinyHunters, the extortion-focused group Mandiant tracks internally as UNC6240.
The vulnerability at the center of the campaign is CVE-2026-35273, an unauthenticated remote code execution flaw (CVSS 9.8) in PeopleSoft's Environment Management Hub (PSEMHUB), affecting PeopleTools 8.61 and 8.62. It was first exploited as a zero-day between May 27 and June 9, 2026 against academic institutions, before Oracle shipped a patch on June 11, 2026. Google's September 2026 advisory documents its return — this time against a broader, global set of targets.
The Bypass: A One-Character Trick
The technique attackers are using to evade WAF rules is strikingly simple: URL-encoding the letter "P" in the vulnerable path. A request to /PSEMHUB/hub gets rewritten as /%50SEMHUB/hub. WAF rules that match the literal string PSEMHUB in a request path miss the encoded variant entirely — but the underlying PeopleSoft/WebLogic application stack decodes the URL before routing it, so the request still reaches the vulnerable handler exactly as intended.
Google warns that other encodings and mixed-case variants of the same trick could follow, meaning organizations relying solely on string-matching WAF rules for this vulnerability should not consider themselves protected even if such a rule is already in place.
Campaign at a Glance
| Attribute | Detail |
|---|---|
| Vulnerability | CVE-2026-35273 — unauthenticated RCE in PeopleSoft Environment Management Hub (PSEMHUB), CVSS 9.8 |
| Affected versions | PeopleSoft Enterprise PeopleTools 8.61 and 8.62 |
| Original zero-day window | May 27 – June 9, 2026 (academic institutions) |
| Oracle patch | June 11, 2026 |
| Renewed campaign identified | September 2026, by Google Threat Intelligence Group / Mandiant |
| Evasion technique | URL-encoding "P" as %50 (e.g. /%50SEMHUB/hub) to bypass literal-string WAF rules |
| Attributed actor | ShinyHunters, tracked by Mandiant as UNC6240 |
| Targeted sectors | Higher education, technology, IT services, healthcare, agriculture, transportation, government |
| Scale | "Dozens" of newly compromised systems identified globally |
Tooling Deployed Post-Compromise
Once inside, the campaign deploys a mix of custom and off-the-shelf tooling:
- JSP web shells — files named
x.jspandu.jspdropped for persistent command access. - SIDEEYE — a C++ backdoor supporting credential theft, file and process management, and reverse-shell functionality.
- Ple64.exe — a trojanized installer used to establish footholds.
- Neo-reGeorg — an open-source tunneling tool used to pivot through the compromised host.
- MeshAgent — legitimate remote-monitoring-and-management (RMM) software repurposed for long-term persistence.
Who Is ShinyHunters
ShinyHunters, tracked by Mandiant as UNC6240, rebranded from the earlier GnosticPlayers identity around 2020 and has operated primarily as a data-theft extortion actor rather than a traditional ransomware crew — stealing data and threatening publication rather than encrypting systems. The group has been separately linked this year to a breach of the FBI's FBIJobs.gov recruiting portal, reportedly via a different PeopleSoft zero-day, underscoring a pattern of targeting the same enterprise software family across multiple campaigns.
Recommendations
For Oracle PeopleSoft Administrators
- Confirm the June 11, 2026 patch for CVE-2026-35273 is applied — this is the only complete fix. WAF rules are not a substitute.
- Disable or remove the Environment Management Hub (PSEMHUB) if it is not actively required.
- Scan WebLogic access logs for requests to
/PSEMHUB/and percent-encoded variants such as/%50SEMHUB/, including mixed-case permutations. - Inspect
PSEMHUB.warand related deployment directories for unauthorized JSP files, particularlyx.jspandu.jsp.
For Security and Incident Response Teams
- Rotate credentials for any PeopleSoft-associated accounts on systems that were internet-facing and unpatched during either exploitation window.
- Monitor database audit logs for bulk queries and unusual outbound traffic originating from PeopleSoft hosts.
- Do not treat WAF coverage as verification of remediation — this campaign specifically demonstrates that literal-string WAF rules can be bypassed while the underlying flaw remains unpatched.