ShinyHunters Bypass WAF Workarounds to Mass-Exploit Unpatched Oracle PeopleSoft Worldwide
ShinyHunters are back on the June PeopleSoft flaw, slipping past firewall rules by encoding a single letter in the URL. Google has warned more than 100 organizations and found web shells on dozens of systems.

Organizations that blocked an Oracle PeopleSoft bug with a firewall rule instead of patching it are getting hacked anyway. The ShinyHunters crew has found that swapping one letter in a URL for its encoded form walks straight past the block.
Google's Mandiant and Threat Intelligence Group described the campaign on September 25. They track the group as UNC6240, and say they have notified more than 100 organizations. Web shells turned up on dozens of systems in higher education, tech, IT services, healthcare, agriculture, transportation and government.
One percent sign
The flaw is CVE-2026-35273 in PeopleSoft's Environment Management Hub, or PSEMHUB. ShinyHunters first exploited it as a zero-day between May 27 and June 9. Oracle issued a security alert on June 10.
Many teams took the fast route: a web application firewall rule that blocks any request to /PSEMHUB/. The new wave requests /%50SEMHUB/ instead. %50 is simply the URL-encoded letter P.
The WAF compares the raw path, sees no match and lets the request through. WebLogic, behind it, decodes the path and hands the request to the vulnerable servlet. One character undoes the whole workaround.
What lands on the box
Before firing the exploit, the attackers send serialized Java POST requests to check whether a target is exposed. Once in, they drop JSP web shells named x.jsp and u.jsp. Mandiant also saw a fileless command path that leaves less on disk.
On Windows hosts, the crew deploys Ple64.exe, a signed, trojanized installer for the Light Alloy media player. It drops SIDEEYE, a backdoor that steals credentials, opens a reverse shell and acts as a proxy. Neo-reGeorg tunnels and the MeshAgent remote management tool keep the access alive.
The group has been busy on other fronts too, recently hijacking Clop's leak site.
Patch, not filter
Mandiant's advice is blunt: apply Oracle's fix and stop relying on the WAF. A filter that matches strings can be beaten by any trick that changes the string but not its meaning.
Not every PeopleSoft customer has been breached, and the bug is not new. The campaign targets the June flaw on systems that never got the patch.
Separately, Cybernews and Hackread have covered claims that the FBI's PeopleSoft environment was also hit. Mandiant says it has no evidence tying that incident to this CVE.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free