Vulnerabilities · 20h ago

UNC6240 Bypasses PeopleSoft WAF Rules Again

Mandiant says UNC6240, also tracked as ShinyHunters, has renewed mass exploitation of Oracle PeopleSoft CVE-2026-35273 after changing its request path by one URL-encoded character. The new wave moved beyond the June focus on higher education and now includes dozens of web shells on systems across multiple sectors worldwide.

The trick is simple: the attacker asks for /%50SEMHUB/ instead of /PSEMHUB/, so a path-based WAF sees a different string and lets it through, while the PeopleSoft application server decodes the path and still routes the request to the vulnerable servlet. That means perimeter rules that only match the literal URL can look effective while the backend remains reachable.

For organizations using PeopleSoft Environment Management Hub controls, the exposure sits at the boundary between filtering and application routing, not just in the product version list. If the request is decoded after the filter checks it, a blocked endpoint can still be hit and turned into a web shell foothold.

CVE-2026-35273

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Known ransomware campaign use. EPSS 9% (95th percentile).

CISA federal remediation date Jun 15 · date passed

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-09-26

Editions

Related stories