Skip to content
RegionAmericas

MediumII Cyber Warfare & Critical Infrastructure26 September 2026, Saturday

Mandiant: ShinyHunters re-exploits 9.8-rated PeopleSoft flaw in 7 sectors by encoding one character to evade WAFs; 25% of commands at top privilege

Google Mandiant disclosed on 26 September that ShinyHunters-linked UNC6240 is again mass-exploiting CVE-2026-35273, patched in June, by URL-encoding a single character in the request path to slip past web application firewalls. Dozens of systems have been compromised in sectors ranging from higher education to government.

Location: USA

According to a BleepingComputer report on 26 September, CVE-2026-35273 is an unauthenticated remote code execution flaw in the Environment Management Hub (PSEMHUB) component of Oracle PeopleSoft; the first zero-day exploitation was reported on 10 June and Oracle released a patch on 11 June. According to Mandiant, the attackers circumvent rules blocking the /PSEMHUB/ path with a /%50SEMHUB/ request: many WAFs inspect the path before decoding it, while WebLogic decodes the request and routes it to the vulnerable component. In the reconnaissance phase, 5 to 15 POST requests containing serialised Java objects are sent to the target, after which the x.jsp, u.jsp and u2.jsp web shells, the SIDEEYE backdoor, the Neo-reGeorg tunnelling tool and the MeshAgent remote management software are deployed.

According to a report by The Hacker News on 26 September, dozens of systems in 7 sectors (higher education, technology, IT services, healthcare, agriculture, transport and government) were compromised through the flaw, which carries a CVSS score of 9.8; around 25% of the attacker's commands ran with root or SYSTEM privileges. Mandiant warned more than 100 organisations with exposed endpoints. The group is continuing its pattern of stealing data and demanding ransom under threat of publication. The disclosure came in the same week as a claim that ShinyHunters stole 2–3 TB of data from the FBI's FBIJobs.gov portal using a different PeopleSoft zero-day; that claim could not be independently verified. Rather than relying solely on WAF rules, Mandiant recommends installing the patch, searching WebLogic logs for encoded variants and rotating credentials.

Talay assessment

Bottom line

Although the patch was released in June, the new wave shows that many organisations are making do with WAF rules instead of patching, and that those rules can be defeated by a single encoded character. The warning to more than 100 organisations and the fact that a quarter of commands ran with the highest privileges point to a rise in data theft and extortion notifications in the coming weeks. The most likely path is new victim listings and tougher pressure to patch.

Likely effects

  • Corporate data securityNegativeWeeks

    Because PeopleSoft holds human resources, student and finance data, successful intrusions turn into personal data leaks and extortion demands; universities and public bodies are first in line.

  • Defensive practiceUncertain1–6 months

    The defeat of path-matching WAF rules through pre-decoding inspection undermines confidence in virtual patching and forces organisations towards real patching and log review.

  • TürkiyeNegativeWeeks

    Turkish universities and companies using Oracle PeopleSoft fall within the same sector profile; checking whether the patch is installed and scanning WebLogic logs for encoded paths is a near-term control item.

Possibilities, ranked

  1. 1
    Extortion and leak listings55%

    ShinyHunters publishes data from new victims, and the number of notifications rises, particularly in higher education and healthcare.

    Watch: New PeopleSoft-related victim listings on the ShinyHunters leak site

  2. 2
    Official warning and mandatory patching30%

    CISA or national CERTs issue an urgent advisory and a patch deadline for the flaw, and the campaign slows.

    Watch: Status of CVE-2026-35273 in the CISA KEV catalogue and the federal patch deadline

  3. 3
    Limited impact15%

    Most organisations turn out to have installed the June patch, and the number of compromised systems stays in the dozens.

    Watch: An updated count of affected systems from Mandiant or Oracle

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • CVSS score▼ 9.8
  • Organisations warned (Mandiant)▼ 100+
  • Share of top-privilege commands▼ 25%

Sources

  1. BleepingComputer — ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
  2. The Hacker News — Attackers bypass WAFs to exploit Oracle PeopleSoft flaw and deploy web shells