
Mandiant Warns ShinyHunters Bypass WAFs to Resume PeopleSoft Mass Exploitation
Mandiant and Google Threat Intelligence Group say UNC6240, tracked as ShinyHunters, is again exploiting PeopleSoft CVE-2026-35273 by requesting a URL-encoded PSEMHUB path that literal WAF rules miss.
Priya Shah, Threat IntelSingapore5 min read
SINGAPORE - Mandiant and Google Threat Intelligence Group said on September 25, 2026, that UNC6240, which they track as ShinyHunters, has resumed mass exploitation of Oracle PeopleSoft CVE-2026-35273 by changing the request path so that web application firewall rules written for the literal Environment Management Hub endpoint no longer match.

The September post updates Mandiant's June 2026 report. In June, UNC6240 exploited the flaw as a zero-day between May 27 and June 9, 2026, predominantly against higher education. Oracle released an out-of-band Security Alert on June 10, 2026. That earlier write-up described CVE-2026-35273 as critical remote code execution in the Environment Management component, scored CVSS 9.8, and aligned with targeting of Environment Management Hub (PSEMHUB) endpoints.

The new wave uses a one-character encoding bypass. UNC6240 requests /%50SEMHUB/ instead of /PSEMHUB/. Mandiant and GTIG said many WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet. %50 is the encoded form of the letter P. They said defenders should assume any percent-encoded, mixed-case, or otherwise non-normalized variant of /PSEMHUB/, and should block on the normalized path. WAF rules and path blocking are not a substitute for the patch.

Mandiant and GTIG said the actor expanded targeting and deployed web shells on dozens of systems globally, spanning higher education, technology, IT services, healthcare, agriculture, transportation, and government. To reach shells behind some load-balanced environments, the actor sent a burst of POST requests to /%50SEMHUB/hub, then created JSP files such as x.jsp, or sequentially numbered JSP files, in the PSEMHUB.war directory. The post also describes u.jsp and u2.jsp used to upload and execute a 5.2 MB binary named Ple64.exe, tracked as SIDEEYE, inside that directory. Other file names called out for hunting include tunnel.jsp and tunnel.jspx.
For security operations teams, Mandiant's immediate list is to apply the Oracle Security Alert patch for CVE-2026-35273, and to disable the Environment Management Hub service in multi-server configurations or remove the PSEMHUB application in single-server configurations, as Oracle's alert describes. Hunt PIA WebLogic access logs for /PSEMHUB/ and percent-encoded variants, especially POST requests to /hub and requests for .jsp files from external addresses. Inspect the PSEMHUB.war directory for files that are not part of the shipped product, including x.jsp, u.jsp, tunnel.jsp, tunnel.jspx, and Ple64.exe. Rotate credentials readable by the PeopleSoft application service account, including database connection strings in psappsrv.cfg, Integration Broker credentials, and cloud credentials reachable from the web tier. A host that only shows the encoded request, with no follow-on activity, may have been validated but not yet exploited.

Sources:
Priya Shah covers threat intelligence for SOCtember from Singapore.
Related stories
Threat Intel
Arista Confirms Actively Exploited VeloCloud Orchestrator Flaw
Threat Intel
Talos Documents CLOSEDQUORUM, Windows Implant That Lets AI Models Vote on C2 Moves
Response
F5 Warns of Exploited BIG-IP APM Flaw Enabling Unauthenticated Remote Code Execution
Response