Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

Redacted leak-site notice beside a data listing that claims campus and payment records.
Leak-site notice and data listing. Identifiers redacted. Not a SOCtember recreation.

Threat Intel

Mandiant Warns ShinyHunters Bypass WAFs to Resume PeopleSoft Mass Exploitation

Mandiant and Google Threat Intelligence Group say UNC6240, tracked as ShinyHunters, is again exploiting PeopleSoft CVE-2026-35273 by requesting a URL-encoded PSEMHUB path that literal WAF rules miss.

Priya Shah, Threat IntelSingapore5 min read

SINGAPORE - Mandiant and Google Threat Intelligence Group said on September 25, 2026, that UNC6240, which they track as ShinyHunters, has resumed mass exploitation of Oracle PeopleSoft CVE-2026-35273 by changing the request path so that web application firewall rules written for the literal Environment Management Hub endpoint no longer match.

Laptop screen showing the PeopleSoft wordmark.
PeopleSoft wordmark on a laptop. Not a photograph of a compromised system.PeopleSoft, the application UNC6240 is exploiting again.

The September post updates Mandiant's June 2026 report. In June, UNC6240 exploited the flaw as a zero-day between May 27 and June 9, 2026, predominantly against higher education. Oracle released an out-of-band Security Alert on June 10, 2026. That earlier write-up described CVE-2026-35273 as critical remote code execution in the Environment Management component, scored CVSS 9.8, and aligned with targeting of Environment Management Hub (PSEMHUB) endpoints.

Oracle wordmark over a dark building and red sky.
Graphic: OracleOracle issued the out-of-band alert for CVE-2026-35273 on June 10, 2026.

The new wave uses a one-character encoding bypass. UNC6240 requests /%50SEMHUB/ instead of /PSEMHUB/. Mandiant and GTIG said many WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet. %50 is the encoded form of the letter P. They said defenders should assume any percent-encoded, mixed-case, or otherwise non-normalized variant of /PSEMHUB/, and should block on the normalized path. WAF rules and path blocking are not a substitute for the patch.

SOCtember diagram comparing a blocked /PSEMHUB/ path with an encoded /%50SEMHUB/ path.
Illustration: SOCtember. Conceptual WAF path bypass, UNC6240 / CVE-2026-35273. Not a vendor UI.A literal path block, and the encoded path Mandiant said still reaches the servlet.

Mandiant and GTIG said the actor expanded targeting and deployed web shells on dozens of systems globally, spanning higher education, technology, IT services, healthcare, agriculture, transportation, and government. To reach shells behind some load-balanced environments, the actor sent a burst of POST requests to /%50SEMHUB/hub, then created JSP files such as x.jsp, or sequentially numbered JSP files, in the PSEMHUB.war directory. The post also describes u.jsp and u2.jsp used to upload and execute a 5.2 MB binary named Ple64.exe, tracked as SIDEEYE, inside that directory. Other file names called out for hunting include tunnel.jsp and tunnel.jspx.

For security operations teams, Mandiant's immediate list is to apply the Oracle Security Alert patch for CVE-2026-35273, and to disable the Environment Management Hub service in multi-server configurations or remove the PSEMHUB application in single-server configurations, as Oracle's alert describes. Hunt PIA WebLogic access logs for /PSEMHUB/ and percent-encoded variants, especially POST requests to /hub and requests for .jsp files from external addresses. Inspect the PSEMHUB.war directory for files that are not part of the shipped product, including x.jsp, u.jsp, tunnel.jsp, tunnel.jspx, and Ple64.exe. Rotate credentials readable by the PeopleSoft application service account, including database connection strings in psappsrv.cfg, Integration Broker credentials, and cloud credentials reachable from the web tier. A host that only shows the encoded request, with no follow-on activity, may have been validated but not yet exploited.

Operations floor with analysts at workstations. Not a photograph of this incident.
Operations desk photograph. Not a picture of this incident.Desk art only. Not a picture of a PeopleSoft intrusion.

Sources:


Priya Shah covers threat intelligence for SOCtember from Singapore.

Related stories

Threat Intel desk