ShinyHunters Exploits Oracle PeopleSoft Vulnerability, Bypasses WAFs in Global Campaign
A known critical vulnerability in **Oracle PeopleSoft**, **CVE-2026-35273**, is under renewed mass exploitation by the threat group linked to **ShinyHunters**. This campaign targets various sectors globally, leveraging a WAF bypass to deploy web shells and sophisticated backdoors, leading to potential data theft and extortion.

**Google** has issued a warning regarding a widespread exploitation campaign targeting a previously identified security flaw in **Oracle PeopleSoft**. The activity, linked to the **ShinyHunters** group, centers on weaponizing **CVE-2026-35273** (CVSS score: 9.8), a critical vulnerability that enables unauthenticated remote code execution.
### A Resurgent Threat
**CVE-2026-35273** was initially exploited as a zero-day against academic institutions. Early attacks involved reconnaissance, deployment of remote access tools like **MeshCentral** agents for persistence, lateral movement via SSH, and data exfiltration. At that time, **Google**-owned **Mandiant** notified over 100 global organizations with vulnerable endpoints, primarily in the U.S.
This latest wave of attacks, attributed to the threat actor **UNC6240**, demonstrates an evolved exploit technique. **Mandiant** reports that **UNC6240** has modified its exploit to circumvent web application firewall (WAF) rules that block the vulnerable **Environment Management Hub (PSEMHUB)** endpoint.
### WAF Bypass Technique
The WAF bypass is achieved by URL-encoding a single character in the request path, specifically requesting `/%50SEMHUB/` instead of `/PSEMHUB/`. Many WAFs and reverse proxies match the literal path before URL decoding, while the **PeopleSoft** application server correctly decodes the request and routes it to the vulnerable servlet, thus bypassing the protection.
### Broad Sector Targeting
The current campaign targets a diverse range of sectors, including higher education, technology, IT services, healthcare, agriculture, transportation, and government. Attackers have successfully deployed web shells on dozens of systems across these industries.
### The Attack Chain Unpacked
The exploitation unfolds through a multi-stage process:
* **Target Identification**: Sending POST requests to `/%50SEMHUB/hub` containing a serialized Java object to identify susceptible systems.
* **WAF Evasion**: Utilizing the URL-encoded `P` (`%50`) in the request path to bypass string-based WAF rules.
* **Code Execution**: Abusing Java deserialization in the **PSEMHUB** hub servlet to deploy web shells and achieve fileless command execution.
* **Web Shell Deployment**: Dropping two JSP web shells, `x.jsp` and `u.jsp`, into the `PSEMHUB.war` directory. `x.jsp` facilitates cross-platform command execution, while `u.jsp` allows chunked file uploads and command execution via `cmd.exe`.
* **Backdoor Installation**: Using `u.jsp` to upload `Ple64.exe`, a trojanized installer that loads **SIDEEYE** in memory. **SIDEEYE** is a C++ backdoor communicating with an external server (`162.219.30[.]165`) over TCP, enabling credential theft, process/file management, interactive reverse shells, and reverse proxy capabilities.
* **Persistent Access**: Deploying the open-source **Neo-reGeorg** tunneling toolkit and the legitimate RMM tool **MeshAgent** on Linux systems for persistent access.

Roughly a quarter of the commands executed by the threat actor were performed with root or `NT Authority\SYSTEM` privileges, granting full control over the operating system. The remaining commands were run under **PeopleSoft** or **WebLogic** service accounts.
### Mitigation Strategies
Organizations are urged to take immediate action to counter this threat:
* **Patching**: Apply all available patches for **CVE-2026-35273**.
* **Service Disablement**: In multi-server configurations, disable the **Environment Management Hub (EMHub)** service. For single-server setups, entirely remove the **PSEMHUB** application.
* **Log Review**: Scrutinize **WebLogic** access logs for requests to `"/PSEMHUB/"` and any percent-encoded variants.
* **Artifact Inspection**: Inspect the `"PSEMHUB.war"` directory for JSP web shells and other malicious artifacts.
* **Credential Rotation**: Rotate all credentials readable by the **PeopleSoft** application service account.
* **Host Hunting**: Search **PeopleSoft** and database hosts for large archive files in temporary or web-accessible directories.
* **Database Audit**: Review database audit logs for bulk queries or exports targeting HR, payroll, and student records tables.
* **Traffic Monitoring**: Monitor outbound traffic from **PeopleSoft** hosts for unusual activity.
### Extortion and FBI Breach Claims
**Google** highlights that **UNC6240** has a history of data theft extortion, where stolen data is threatened for public release unless a ransom is paid. Affected organizations should prepare for potential extortion attempts and monitor for public exposure of their data.
This disclosure coincides with **ShinyHunters'** claims of breaching the U.S. Federal Bureau of Investigation's (**FBI**) `FBIJobs.gov` portal (which remains inaccessible). The group alleges they stole 2-3 TB of sensitive data to refute allegations made by the agency in a May 2026 alert.
A **ShinyHunters** spokesperson stated that this **FBI** breach was not financially motivated and did not involve **CVE-2026-35273**, but rather a different zero-day vulnerability in **Oracle PeopleSoft**. The group also revealed their rebranding from **GnosticPlayers** to **ShinyHunters** in 2020.