In June, a lot of PeopleSoft teams bought time the sensible way: a web application firewall rule that blocked the vulnerable Environment Management Hub path while the real patch waited for a change window. Google now says ShinyHunters has a way past that rule, and it is almost insultingly small. The attackers encode the first letter of the path. The WAF sees a string it does not recognize. PeopleSoft decodes it and runs the request anyway.
If your HR, payroll, finance, or student records live on PeopleSoft and the June fix is not actually installed, this is the week to close it for real.
A WAF rule that matches the text of a path is not a patch. It is a spelling test, and attackers can spell.
The 5-Minute Cyber BriefDon’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
What happened
Mandiant and Google Threat Intelligence Group (GTIG) reported over the weekend a renewed mass-exploitation wave against CVE-2026-35273, the unauthenticated remote code execution flaw in PeopleSoft Enterprise PeopleTools (Updates Environment Management, versions 8.61 and 8.62) that Oracle fixed in an out-of-band Security Alert on June 10, 2026. Google tracks the actor as UNC6240, the group better known as ShinyHunters. It exploited the same bug as a zero-day in late May and early June, mostly against universities.
Back then, the advice for teams that could not patch immediately was to block external access to /PSEMHUB/*. According to Google, the group now sends its requests to /%50SEMHUB/hub instead. %50 is the URL-encoded letter P. Many WAFs and reverse proxies compare the literal path before decoding it, so the rule never fires, while WebLogic decodes the request and routes it to the vulnerable servlet.
The new wave has placed web shells on dozens of systems in higher education, technology, IT services, healthcare, agriculture, transportation, and government. Google describes a quiet sequence: five to 15 POST requests carrying serialized Java objects that return host details without writing files, then exploitation that runs commands in memory or drops small JSP web shells (x.jsp, u.jsp, u2.jsp) in the PSEMHUB application directory. On Windows servers the attackers loaded a backdoor Google calls SIDEEYE through a trojanized installer named Ple64.exe. They also staged the Neo-reGeorg tunneling kit and used the legitimate MeshAgent remote management tool on Linux hosts. About a quarter of the commands ran as root or SYSTEM.
The timing overlaps with the FBI story. Over the weekend the FBI reportedly told employees in an internal notice that names, addresses, job titles, and Social Security numbers were exposed in the hack of its FBIJobs.gov portal. ShinyHunters says it got in through PeopleSoft and claims a separate, new flaw in the same PSEMHUB component. That claim is not verified. The group did tell BleepingComputer it used this WAF bypass against FBI Jobs.
Why it matters
PeopleSoft is where organizations keep the records people least want leaked: payroll, HR files, student data, bank details for direct deposit. ShinyHunters runs data-theft extortion, and Google tells affected organizations to prepare for ransom notes and possible publication of stolen data.
The bigger lesson is about “mitigated” tickets. Plenty of teams closed this one in June with a WAF rule and moved on. That rule may still show green in every dashboard while the hub behind it is reachable. If the risk register says “mitigated by WAF,” it needs a second look.
What to do first
- Patch. Apply Oracle’s Security Alert fix for CVE-2026-35273 on every PeopleTools 8.61 and 8.62 environment, including test and training copies that face the Internet.
- Turn off what you do not use. Disable the Environment Management Hub (EMHub) service in multi-server configurations, or remove the PSEMHUB application entirely on single-server setups.
- Fix the rule, then stop relying on it. If you keep a WAF or proxy block, match on the decoded, case-normalized path. Treat it as a speed bump, not the fix.
- Look for the knock. Search WebLogic access logs for
/PSEMHUB/and any percent-encoded or mixed-case variant, such as/%50SEMHUB/. - Rotate. If anything turns up, rotate every credential the PeopleSoft application service account can read, including database connection strings.
- Plan the call. Tell legal and communications now what an extortion email would trigger, so nobody improvises if one arrives.
Forward this
If your organization runs Oracle PeopleSoft for HR, payroll, finance, or student records: please confirm this week that Oracle’s June 10 security fix is actually installed, not just blocked at the firewall. Google says the ShinyHunters extortion group is getting past firewall rules with a one-letter trick and has planted web shells on dozens of servers. Ask the team that runs PeopleSoft for a yes or no, and whether the Environment Management Hub can be switched off.
Details
- CVE-2026-35273: unauthenticated remote code execution in PeopleSoft Enterprise PeopleTools, Updates Environment Management component, over HTTP; CVSS 3.1 base score 9.8
- Affected supported versions: PeopleTools 8.61 and 8.62 (Oracle notes earlier unsupported releases are likely affected too)
- Fix: Oracle Security Alert, released June 10, 2026
- KEV: CISA added the flaw to the Known Exploited Vulnerabilities catalog on June 12, 2026
- Actor: UNC6240 (ShinyHunters); zero-day exploitation first seen late May to early June 2026
- New technique: URL-encoded path
/%50SEMHUB/hubbypasses string-matching WAF rules; Google warns other encodings and mixed case may follow - Tooling: JSP web shells
x.jsp,u.jsp,u2.jsp,tunnel.jsp/tunnel.jspx(Neo-reGeorg); SIDEEYE backdoor viaPle64.exe; MeshAgent on Linux
Hunt / verify
- Grep WebLogic access logs for
SEMHUBcase-insensitively and for%50,%53, and other encoded characters nearSEMHUB. Pay attention to bursts of POST requests to/hub. - List the
PSEMHUB.wardirectory on every web node and look for JSP files you did not deploy. - Check Windows PeopleSoft hosts for
Ple64.exe, and Linux hosts for an unexpected MeshAgent install. - Look for large archive files in temporary or web-accessible directories on PeopleSoft and database hosts.
- Review database audit logs for bulk queries or exports against HR, payroll, and student tables, and watch outbound traffic from PeopleSoft servers.
Slack paste: PeopleSoft: confirm Oracle’s June 10 fix for CVE-2026-35273 is installed (not just WAF-blocked), disable EMHub/PSEMHUB if unused, grep WebLogic logs for encoded /PSEMHUB/ (e.g. /%50SEMHUB/), check PSEMHUB.war for stray JSPs.
Sources
- BleepingComputer: ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks (Sep 26, 2026)
- SecurityWeek: Google warns of ShinyHunters’ fresh Oracle PeopleSoft campaign (Sep 28, 2026)
- The Hacker News: Attackers bypass WAFs to exploit Oracle PeopleSoft flaw and deploy web shells
- Hackread: ShinyHunters bypass WAF rules to resume Oracle PeopleSoft attacks
- Oracle Security Alert Advisory: CVE-2026-35273
- CISA: Adds one Known Exploited Vulnerability to catalog (Jun 12, 2026)
- TechCrunch: FBI reportedly declares cyber security incident after hackers steal agents’ personal data (Sep 28, 2026)
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.