The useful part
In June, the threat actor exploited this vulnerability as a zero-day predominantly against academic institutions. The threat actor bypassed these string-based WAF rules by URL-encoding a single character in the request path, requesting /%50SEMHUB/ in place of /PSEMHUB/. Many WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet.
How it works
- Mandiant recommends that organizations running Oracle PeopleSoft take the following immediate actions.
- On hosts that the threat actor validated but did not yet exploit, organizations may see this request in logs, with no follow-on activity.
- Post-Exploitation Tooling Dual Web Shells To establish persistent access and stage follow-on payloads, the threat actor deployed two complementary, single-line JSP web shells into the PSEMHUB.war directory.
- To access web shells behind some load balanced environments, the threat actor sent a burst of multiple POST requests to /%50SEMHUB/hub, followed by the creation of a new JSP files, such as x.jsp, or...
- This allows the threat actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure.
What to take from it
ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft | Google Cloud Blog Threat Intelligence ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft September 25, 2026 Mandiant Mandiant Services Stop attacks, reduce risk, and advance your security. Additional remediation and hardening guidance is included later in this post. Remediation and Hardening Quick Guide Apply the Oracle Security Alert patch for CVE-2026-35273.
Example or evidence
- The current campaign demonstrates that UNC6240 adapted to published defensive guidance, targeting organizations that implemented WAF rules but did not patch the vulnerability.
- Inspect /webserv/ /applications/peoplesoft/PSEMHUB.war/ for files that are not part of the shipped product, including but not limited to x.jsp, u.jsp, tunnel.jsp, tunnel.jspx, and Ple64.exe.
- From Zero-Day to N-Day In June 2026, we reported a UNC6240 campaign that exploited CVE-2026-35273 as a zero-day between May 27 and June 9, 2026, predominantly against higher education institutions.
- Target Verification Before exploitation, targeted servers typically received five to 15 POST requests to /%50SEMHUB/hub containing a serialized Java object.
Details worth keeping
Our analysis indicates that the threat actor expanded their targeting in this recent campaign, deploying web shells on dozens of systems globally, spanning higher education, technology, IT services, healthcare, agriculture, transportation, and government. WAF rules and path-based blocking are not a substitute for patching. Oracle released an out-of-band Security Alert on June 10, 2026.
Related coverage
- Gbhackers: Oracle PeopleSoft servers vulnerable to CVE-2026-35273.
- Thehackernews: Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.
- Cybersecuritynews: ShinyHunters has renewed attacks against Oracle PeopleSoft systems by slipping past web application firewall protections and planting web shells.
- Investing: ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google says