PeopleSoft attacks are back and slip past WAF rules: Oracle’s June patch for CVE-2026-35273 is the only fix
EditorialBy TrustList Editorial
Google’s threat intelligence team says the ShinyHunters group is again exploiting PeopleSoft’s CVE-2026-35273, encoding one letter of the path to get past WAF rules. Apply Oracle’s June security alert, disable EMHub and hunt for web shells.
- Cybersecurity
- Cybersecurity Software
- Vulnerability Management
- Oracle
- +3 more
About PeopleSoft attacks are back and slip past WAF rules: Oracle’s June patch for CVE-2026-35273 is the only fix
PeopleSoft attacks are back and slip past WAF rules: Oracle's June patch for CVE-2026-35273 is the only fix
26 September 2026 — Google's threat intelligence team (Mandiant) reported on 26 September 2026 that the extortion group it tracks as UNC6240, better known as ShinyHunters, has started a new round of mass exploitation of Oracle PeopleSoft through CVE-2026-35273. The flaw was first exploited as a zero-day between 27 May and 9 June 2026, and Oracle issued an out-of-band Security Alert for it on 10 June. Organisations that shielded PeopleSoft with firewall rules instead of patching are the ones now being hit.
How the new attacks get through
The vulnerable component is the Environment Management Hub (EMHub), reached under the path /PSEMHUB/. Many web application firewalls and reverse proxies were given rules that block that literal path. The attackers now request /%50SEMHUB/ instead, where %50 is the encoded form of the letter P. The rules compare the path before decoding it; PeopleSoft's application server decodes it and routes the request to the vulnerable servlet anyway.
Google says web shells have been planted on dozens of systems worldwide, in higher education, technology, IT services, healthcare, agriculture, transport and government. SecurityWeek reported on 28 September that the modified exploit may be linked to a breach claim involving FBI job portals; that link is not confirmed by Google.
Who is affected
Any organisation running PeopleSoft (HR, payroll, student administration, finance) that has not applied Oracle's Security Alert for CVE-2026-35273, including those that rely on WAF or path blocking. Google is explicit: "WAF rules and path-based blocking are not a substitute for patching."
What to do
Google's recommendations, in short:
- Apply Oracle's Security Alert patch for CVE-2026-35273.
- Disable EMHub in multi-server set-ups, or remove the PSEMHUB application in single-server ones.
- Search the PIA WebLogic access logs for
/PSEMHUB/and any percent-encoded variant, especially POST requests to/huband requests for.jspfiles from outside. - Look in the PSEMHUB.war and PORTAL.war directories for files that are not part of the product, such as
x.jsp,u.jsp,tunnel.jspandPle64.exe. - Rotate every credential the PeopleSoft service account can read: database strings in
psappsrv.cfg, Integration Broker credentials and any cloud keys reachable from the web tier. - Watch for unexpected MeshCentral agents, shells started by the WebLogic Java process, and large archives or bulk queries against HR, payroll and student tables.
- Prepare for extortion contact; the group's pattern is to steal data and then demand payment.
If a managed-service provider or hosting partner runs PeopleSoft for you, ask them in writing whether the June patch is applied and whether the logs have been searched for the encoded path.
Sources
Categories & features
- Cybersecurity
- Cybersecurity Software
- Vulnerability Management
- Oracle
- ERP
- ERP Software
- Payroll Software
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.