Vulnerabilities · 14h ago

ShinyHunters Reroute PeopleSoft Exploits Around WAFs

Google and Mandiant say ShinyHunters, tracked as UNC6240, has moved into a second wave of Oracle PeopleSoft exploitation by changing its CVE-2026-35273 request path to slip past web application firewall rules. The group is now URL-encoding the PSEMHUB endpoint, which lets attacks resume against systems operators thought were already blocked.

The trick is a decoding mismatch. Many WAF and reverse-proxy rules compare the literal path first, so the encoded request looks harmless to the filter, but the PeopleSoft server decodes it and still routes the request to the vulnerable servlet. That means a perimeter rule can appear to mitigate the issue while leaving the backend reachable for web-shell deployment.

For PeopleSoft and PeopleTools environments, the exposure now sits in the gap between filter logic and application decoding, not just in internet-facing systems with no perimeter controls. In organizations that front the Environment Management Hub with path-based rules, the campaign shows how quickly a blocked endpoint can become reachable again once attackers adjust the string they send.

CVE-2026-35273

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Known ransomware campaign use. EPSS 9% (95th percentile).

CISA federal remediation date Jun 15 · date passed

Timeline

Sources

6 sources covering this story

Entities

Part of the PlainSec briefing for 2026-09-29

Editions

Related stories