PeopleSoft CVE-2026-35273: one encoded letter beats WAFs
ShinyHunters is mass-exploiting Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) again, dodging WAF rules by writing one letter of the path as %50.
3 min read

By the numbers
- CVSS severity of CVE-2026-35273
- 9.8 / 10
- PeopleSoft customers hit in the June zero-day wave
- 100+
- sectors targeted in the new wave
- 7
The hacking group ShinyHunters is breaking into Oracle PeopleSoft servers again, using a flaw Oracle patched in June. This time the attackers slip past web application firewalls by changing a single letter. They write the "P" in /PSEMHUB/ as %50, its URL-encoded form. Firewall rules that block the literal path miss it, while the server decodes the request and runs the attack anyway.
Google's threat intelligence unit Mandiant described the new wave in a report published September 25, 2026. It says the attackers planted web shells on "dozens of systems globally." A web shell is a small script that gives an outsider a command line on the server.
The flaw behind it
The bug is CVE-2026-35273. It sits in PeopleSoft's Environment Management Hub, or PSEMHUB, a component that manages PeopleSoft installations. The Hacker News reports a CVSS score of 9.8 out of 10. CVSS is the standard scale security teams use to rank how dangerous a flaw is.
Mandiant calls it a Java deserialization flaw. The server takes a packaged Java object from a request and rebuilds it without checking it first. A crafted object can make the server run the attacker's code. No login is needed.
Mandiant tracks the group as UNC6240. It says the group first used the bug as a zero-day, meaning before any fix existed, between May 27 and June 9, 2026. Most victims then were universities. Oracle shipped an emergency Security Alert on June 10.
SecurityWeek reports that the June wave hit more than 100 PeopleSoft customers in education. It names the University of Nottingham, the insurance regulator NAIC and Nissan among the victims.
How one letter gets past the firewall
After June, many organizations added firewall rules that block any request to /PSEMHUB/. That stopped the old exploit. It did not fix the bug.
Mandiant explains the gap: "Many WAF and reverse proxy rules match the literal path before URL decoding." The PeopleSoft server, by contrast, decodes the path first. So /%50SEMHUB/ looks harmless to the firewall and identical to /PSEMHUB/ for the server.
Once inside, the group deployed these tools, according to Mandiant:
| Tool | What it does |
|---|---|
x.jsp | Runs commands sent in a POST request |
u.jsp, u2.jsp | Uploads files in 150 KB pieces |
tunnel.jsp, tunnel.jspx | Neo-reGeorg tunnel into the internal network |
Ple64.exe | Tampered Light Alloy media-player installer carrying the SIDEEYE backdoor |
| MeshAgent | Remote-management agent kept for Linux persistence |
The new wave reaches well beyond universities. Mandiant lists technology, IT services, healthcare, agriculture, transportation and government as well as higher education.
Why ShinyHunters matters here
ShinyHunters runs data-theft extortion. It steals data, then threatens to publish it unless the victim pays, SecurityWeek says. Google advises organizations to "prepare for extortion communications" and watch for stolen data appearing online, SecurityWeek notes.
What this means for developers
Install Oracle's patch for CVE-2026-35273. Mandiant says to apply the fix rather than rely on firewall filtering, and this campaign shows why. A blocklist rule matched on a literal string is one encoding trick away from failing.
If you do not use the Environment Management Hub, disable it or remove PSEMHUB entirely, as Mandiant advises. A component that is not deployed cannot be exploited.
Search your WebLogic logs for both /PSEMHUB/ and encoded forms such as /%50SEMHUB/, especially POST requests to the hub. Mandiant also says to check the PSEMHUB.war folder for files you did not put there. Look for unexpected MeshCentral agents too.
If you find signs of entry, rotate database and cloud credentials. An attacker with a shell on PeopleSoft may have read the connection details it uses.
The wider lesson applies to any web application behind a firewall. Rules that match paths should normalize the request first, decoding it the way the server will. Otherwise the firewall and the server are reading two different requests.
Sources
- ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft - Google Cloud (Mandiant)
- Google Warns of ShinyHunters' Fresh Oracle PeopleSoft Campaign - SecurityWeek
- Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells - The Hacker News
Related articles

SharePoint, MikroTik bugs hit CISA's exploited list
CISA added a Microsoft SharePoint Server bug and a MikroTik RouterOS exploit chain to its exploited-vulnerability list, with a patch deadline of September 28 for U.S. federal agencies.

Citrix NetScaler flaws: CISA sets a Sept. 30 deadline
CISA added two Citrix NetScaler flaws, both scoring 9.5 of 10 on the CVSS severity scale, to its exploited-vulnerability list on September 27, giving federal agencies until September 30 to patch.

Kiteworks asks customers to shut down servers this weekend
Kiteworks asked every customer to shut down its servers for six hours on Saturday, September 26, after law enforcement warned of an imminent attack.
The daily brief
Three to five stories a day, and what each one means for the people who build software. Free, no spam.