gcp Google Cloud Blog ·

ShinyHunters Renews Oracle PeopleSoft Exploitation, Bypasses WAF

blogsecuritysecurity-advisoryengineerhealthcaremediaeducationgovernmentenergyautomotive
security announcement

Mandiant and Google Threat Intelligence warn of a renewed mass exploitation campaign by UNC6240 (ShinyHunters) targeting Oracle PeopleSoft's CVE-2026-35273. The threat actor adapted its exploit to bypass web application firewall rules by URL-encoding a single character in the request path, rendering existing WAF protections ineffective. This campaign has led to web shell deployments on dozens of systems globally, affecting higher education, healthcare, government, and other sectors. Organizations running PeopleSoft are urged to apply Oracle's security patch immediately and disable the Environment Management Hub (EMHub) service.

  • →Renewed Exploitation of Oracle PeopleSoft CVE-2026-35273 by ShinyHunters
  • →Immediate Remediation and Hardening Guidance
  • →WAF Bypass and Exploitation Methodology Detailed
Security (3) ›
  • Renewed Exploitation of Oracle PeopleSoft CVE-2026-35273 by ShinyHunters

    Mandiant and Google Threat Intelligence have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), expanding global targeting across multiple sectors beyond the education institutions initially affected. The threat actor modified their exploit to bypass string-based web application firewall (WAF) rules by URL-encoding characters in the request path, specifically using /%50SEMHUB/ in place of /PSEMHUB/.

  • Immediate Remediation and Hardening Guidance

    Organizations running Oracle PeopleSoft are advised to immediately apply the Oracle Security Alert patch for CVE-2026-35273 and disable the Environment Management Hub (EMHub) service or remove the PSEMHUB application. Additional recommendations include searching WebLogic access logs for suspicious requests to /PSEMHUB/ or its percent-encoded variants, inspecting for unauthorized files, rotating PeopleSoft application service account credentials, and monitoring outbound traffic for known indicators.

  • WAF Bypass and Exploitation Methodology Detailed

    The current campaign demonstrates UNC6240's adaptation to published defensive guidance, targeting organizations that implemented WAF rules without patching. The attack lifecycle involves target verification using serialized Java objects, a WAF bypass leveraging URL-encoded paths, and two primary exploitation methods: web shell deployment (e.g., x.jsp, u.jsp) and fileless command execution directly returning output in HTTP responses, making detection more challenging.

Read the original announcement →

https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft/

Related releases