Skip to content
TrustList
News

PeopleSoft attacks are back and slip past WAF rules: Oracle’s June patch for CVE-2026-35273 is the only fix

Editorial

By TrustList Editorial

Google’s threat intelligence team says the ShinyHunters group is again exploiting PeopleSoft’s CVE-2026-35273, encoding one letter of the path to get past WAF rules. Apply Oracle’s June security alert, disable EMHub and hunt for web shells.

About PeopleSoft attacks are back and slip past WAF rules: Oracle’s June patch for CVE-2026-35273 is the only fix

PeopleSoft attacks are back and slip past WAF rules: Oracle's June patch for CVE-2026-35273 is the only fix

26 September 2026 — Google's threat intelligence team (Mandiant) reported on 26 September 2026 that the extortion group it tracks as UNC6240, better known as ShinyHunters, has started a new round of mass exploitation of Oracle PeopleSoft through CVE-2026-35273. The flaw was first exploited as a zero-day between 27 May and 9 June 2026, and Oracle issued an out-of-band Security Alert for it on 10 June. Organisations that shielded PeopleSoft with firewall rules instead of patching are the ones now being hit.

How the new attacks get through

The vulnerable component is the Environment Management Hub (EMHub), reached under the path /PSEMHUB/. Many web application firewalls and reverse proxies were given rules that block that literal path. The attackers now request /%50SEMHUB/ instead, where %50 is the encoded form of the letter P. The rules compare the path before decoding it; PeopleSoft's application server decodes it and routes the request to the vulnerable servlet anyway.

Google says web shells have been planted on dozens of systems worldwide, in higher education, technology, IT services, healthcare, agriculture, transport and government. SecurityWeek reported on 28 September that the modified exploit may be linked to a breach claim involving FBI job portals; that link is not confirmed by Google.

Who is affected

Any organisation running PeopleSoft (HR, payroll, student administration, finance) that has not applied Oracle's Security Alert for CVE-2026-35273, including those that rely on WAF or path blocking. Google is explicit: "WAF rules and path-based blocking are not a substitute for patching."

What to do

Google's recommendations, in short:

  • Apply Oracle's Security Alert patch for CVE-2026-35273.
  • Disable EMHub in multi-server set-ups, or remove the PSEMHUB application in single-server ones.
  • Search the PIA WebLogic access logs for /PSEMHUB/ and any percent-encoded variant, especially POST requests to /hub and requests for .jsp files from outside.
  • Look in the PSEMHUB.war and PORTAL.war directories for files that are not part of the product, such as x.jsp, u.jsp, tunnel.jsp and Ple64.exe.
  • Rotate every credential the PeopleSoft service account can read: database strings in psappsrv.cfg, Integration Broker credentials and any cloud keys reachable from the web tier.
  • Watch for unexpected MeshCentral agents, shells started by the WebLogic Java process, and large archives or bulk queries against HR, payroll and student tables.
  • Prepare for extortion contact; the group's pattern is to steal data and then demand payment.

If a managed-service provider or hosting partner runs PeopleSoft for you, ask them in writing whether the June patch is applied and whether the logs have been searched for the encoded path.

Sources

Categories & features