One Encoded Letter Defeated the WAF: ShinyHunters Resumes Mass PeopleSoft Exploitation
On 26 September 2026 Mandiant and the Google Threat Intelligence Group published an update with an uncomfortable message for everyone who “mitigated” the Oracle PeopleSoft flaw with a firewall rule: UNC6240 — the ShinyHunters-linked cluster — has resumed mass exploitation of CVE-2026-35273, and the new wave works precisely against systems whose operators believed their WAF rules had closed the exposure. The flaw, rated CVSS 9.8, affects supported PeopleSoft Enterprise PeopleTools 8.61 and 8.62, is remotely exploitable without authentication, and can result in remote code execution. In June the actor exploited it as a zero-day against academic institutions between 27 May and 9 June; Oracle issued an out-of-band Security Alert on 10 June. This time the targeting is global and cross-sector — webshells on dozens of systems spanning higher education, technology, IT services, healthcare, agriculture, transportation, and government.
The bypass is almost insultingly small. The vulnerable endpoint is the Environment Management Hub servlet at /PSEMHUB/. Defenders who could not patch or disable it blocked the literal path at the perimeter. UNC6240 modified its exploit to request /%50SEMHUB/ instead — the letter P replaced with its percent-encoded equivalent. Many WAF and reverse-proxy rules match the path string before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet anyway. One encoded character, and the “mitigation” never sees the attack. Mandiant is explicit that WAF rules and path-based blocking are not a substitute for patching — a sentence that should be forwarded to every change board that accepted a WAF rule as a permanent fix, here or for the NetScaler zero-days and the SharePoint RCE now under active exploitation in the same week.
What the responders found — and what to hunt
The campaign tradecraft is industrial, not opportunistic: web-shell deployment at scale and follow-on persistence including unexpected MeshCentral agents phoning out. Mandiant's quick guide gives defenders concrete artifacts. Search PIA WebLogic access logs for requests to /PSEMHUB/ and any percent-encoded variant (such as /%50SEMHUB/) — particularly POST requests to /hub and requests for .jsp files from external source IPs. Inspect the deployed PSEMHUB.war directory for files that are not part of the shipped product, including but not limited to x.jsp, u.jsp, tunnel.jsp, tunnel.jspx, and Ple64.exe. Rotate everything the PeopleSoft application service account can read — database connection strings in psappsrv.cfg, Integration Broker credentials, and any cloud credentials reachable from the web tier — and monitor outbound traffic from PeopleSoft hosts against the network indicators in the report.
The structural lesson generalizes beyond PeopleSoft. String-matching controls placed in front of systems that normalize input differently will always have this gap: the WAF sees one string, the application sees another, and the attacker chooses the encoding both will accept. The same class of mismatch powers the prompt-injection and tool-description attacks this site tracks in agent infrastructure — one layer's “safe” representation becoming another layer's instruction. Patch the endpoint, or remove it: Oracle's own guidance says to disable the EMHub service in multi-server configurations, or remove the PSEMHUB application entirely in single-server ones. A servlet nobody uses cannot be exploited through any encoding.
What to do
- Apply Oracle's Security Alert patch for CVE-2026-35273 now. Treat WAF coverage as already bypassed — because for this actor, it is.
- Disable or remove EMHub per Oracle's guidance. Disable the service in multi-server configurations; remove PSEMHUB entirely where single-server. Unused attack surface should not exist.
- Hunt the encoded variants, not just the literal path. Search WebLogic access logs for
/%50SEMHUB/and other percent-encoded forms, POSTs to/hub, and external.jsprequests. Audit every historical “blocked by WAF” assumption for decode-before-match gaps. - Inspect for shells and rotate service-account secrets. Check
PSEMHUB.warfor non-shipped files, review endpoints for MeshCentral agents, and rotate database strings, broker credentials, and reachable cloud credentials. - Google's notification count is a floor, not a ceiling. More than 100 organizations were notified; dozens are confirmed with shells. If you run PeopleTools 8.61 or 8.62, assume targeting and verify from logs, not from the absence of alerts.
Sources:
- Mandiant / Google Threat Intelligence Group — “ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft” (26 September 2026; UNC6240, /%50SEMHUB/ WAF bypass, cross-sector webshells, remediation guide)
- BleepingComputer — “ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks” (URL-encoding bypass of WAF mitigation, resumed widespread exploitation)
- Cybernews — “ShinyHunters targets PeopleSoft again” (100+ organizations notified; recycled critical flaw CVE-2026-35273)