Google iconGoogleSep 25, 2026 ~7 min source read

ShinyHunters Renew Mass Exploitation of Oracle PeopleSoft by Bypassing WAFs

Mandiant and Google Threat Intelligence Group report UNC6240 (ShinyHunters) updated its exploit for CVE-2026-35273 to bypass string-based WAF rules, expanding attacks beyond higher education and deploying web shells across multiple sectors.

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

Share this story

Send the public story page.

Useful takeaways from this story.

Threat actor UNC6240 adapted its exploit by URL-encoding a single character in the request path (/PSEMHUB/ → /%50SEMHUB/), allowing it to bypass many WAF and reverse proxy rules.

The useful part

In June, the threat actor exploited this vulnerability as a zero-day predominantly against academic institutions. The threat actor bypassed these string-based WAF rules by URL-encoding a single character in the request path, requesting /%50SEMHUB/ in place of /PSEMHUB/. Many WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet.

How it works

  • Mandiant recommends that organizations running Oracle PeopleSoft take the following immediate actions.
  • On hosts that the threat actor validated but did not yet exploit, organizations may see this request in logs, with no follow-on activity.
  • Post-Exploitation Tooling Dual Web Shells To establish persistent access and stage follow-on payloads, the threat actor deployed two complementary, single-line JSP web shells into the PSEMHUB.war directory.
  • To access web shells behind some load balanced environments, the threat actor sent a burst of multiple POST requests to /%50SEMHUB/hub, followed by the creation of a new JSP files, such as x.jsp, or...
  • This allows the threat actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure.

What to take from it

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft | Google Cloud Blog Threat Intelligence ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft September 25, 2026 Mandiant Mandiant Services Stop attacks, reduce risk, and advance your security. Additional remediation and hardening guidance is included later in this post. Remediation and Hardening Quick Guide Apply the Oracle Security Alert patch for CVE-2026-35273.

Example or evidence

  • The current campaign demonstrates that UNC6240 adapted to published defensive guidance, targeting organizations that implemented WAF rules but did not patch the vulnerability.
  • Inspect /webserv/ /applications/peoplesoft/PSEMHUB.war/ for files that are not part of the shipped product, including but not limited to x.jsp, u.jsp, tunnel.jsp, tunnel.jspx, and Ple64.exe.
  • From Zero-Day to N-Day In June 2026, we reported a UNC6240 campaign that exploited CVE-2026-35273 as a zero-day between May 27 and June 9, 2026, predominantly against higher education institutions.
  • Target Verification Before exploitation, targeted servers typically received five to 15 POST requests to /%50SEMHUB/hub containing a serialized Java object.

Details worth keeping

Our analysis indicates that the threat actor expanded their targeting in this recent campaign, deploying web shells on dozens of systems globally, spanning higher education, technology, IT services, healthcare, agriculture, transportation, and government. WAF rules and path-based blocking are not a substitute for patching. Oracle released an out-of-band Security Alert on June 10, 2026.

Related coverage

  • Gbhackers: Oracle PeopleSoft servers vulnerable to CVE-2026-35273.
  • Thehackernews: Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.
  • Cybersecuritynews: ShinyHunters has renewed attacks against Oracle PeopleSoft systems by slipping past web application firewall protections and planting web shells.
  • Investing: ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google says

More context around this story.

Agentic AI Threat Intelligence Essentials
Dzone iconDzoneSep 15, 2026

Agentic AI Threat Intelligence Essentials

Agentic AI can help threat intelligence teams move faster across collection, enrichment, correlation, and drafting while keeping critical judgments in human hands. This Refcard covers the essentials of building agent-supported intelligence workflows, including how to preserve provenance, evaluate source reliability and

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app