ShinyHunters Renews Oracle PeopleSoft Exploitation, Bypasses WAF
Mandiant and Google Threat Intelligence warn of a renewed mass exploitation campaign by UNC6240 (ShinyHunters) targeting Oracle PeopleSoft's CVE-2026-35273. The threat actor adapted its exploit to bypass web application firewall rules by URL-encoding a single character in the request path, rendering existing WAF protections ineffective. This campaign has led to web shell deployments on dozens of systems globally, affecting higher education, healthcare, government, and other sectors. Organizations running PeopleSoft are urged to apply Oracle's security patch immediately and disable the Environment Management Hub (EMHub) service.
- →Renewed Exploitation of Oracle PeopleSoft CVE-2026-35273 by ShinyHunters
- →Immediate Remediation and Hardening Guidance
- →WAF Bypass and Exploitation Methodology Detailed
Security (3) ›
- Renewed Exploitation of Oracle PeopleSoft CVE-2026-35273 by ShinyHunters
Mandiant and Google Threat Intelligence have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), expanding global targeting across multiple sectors beyond the education institutions initially affected. The threat actor modified their exploit to bypass string-based web application firewall (WAF) rules by URL-encoding characters in the request path, specifically using /%50SEMHUB/ in place of /PSEMHUB/.
- Immediate Remediation and Hardening Guidance
Organizations running Oracle PeopleSoft are advised to immediately apply the Oracle Security Alert patch for CVE-2026-35273 and disable the Environment Management Hub (EMHub) service or remove the PSEMHUB application. Additional recommendations include searching WebLogic access logs for suspicious requests to /PSEMHUB/ or its percent-encoded variants, inspecting for unauthorized files, rotating PeopleSoft application service account credentials, and monitoring outbound traffic for known indicators.
- WAF Bypass and Exploitation Methodology Detailed
The current campaign demonstrates UNC6240's adaptation to published defensive guidance, targeting organizations that implemented WAF rules without patching. The attack lifecycle involves target verification using serialized Java objects, a WAF bypass leveraging URL-encoded paths, and two primary exploitation methods: web shell deployment (e.g., x.jsp, u.jsp) and fileless command execution directly returning output in HTTP responses, making detection more challenging.
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft/
Related releases
- Google SecOps SOAR Release 6.3.101 Rolls Out Google Cloud release notes ·
- Google SecOps SOAR Release 6.3.100 Now Available Across All Regions Google Cloud release notes ·
- Cloud Run functions Python runtime 3.10 reaches end of life in 7 days endoflife.date ·
- Compute Engine X5 series now GA with 48TB memory-optimized instances Google Cloud release notes ·
- GKE Standard Clusters Now Support Up to 512 Pods Per Node Google Cloud release notes ·
- Google Cloud Launches API Keys API with MCP Server in Preview Google Cloud release notes ·