The PeopleSoft WAF matched /PSEMHUB/. UNC6240 asked for /%50SEMHUB/.
Mandiant and GTIG on 26 September. CVE-2026-35273 is the June N-day. The literal-path rule is not the patch.
Bottom line up front
CONFIRMED Mandiant and Google Threat Intelligence Group published 26 September 2026 that UNC6240 (publicly ShinyHunters) resumed mass exploitation of CVE-2026-35273 against Oracle PeopleSoft. The June zero-day is now an N-day. The new fact is not a new CVE. It is a one-character URL encoding that walks past the WAF rule a lot of operators used instead of the patch.
The encoded path Mandiant documented is /%50SEMHUB/ in place of /PSEMHUB/. %50 is the letter P. Many WAF and reverse-proxy rules match the literal string before decoding. WebLogic then decodes the path and routes it to the Environment Management Hub servlet. Mandiant’s sentence: operators may have believed the WAF had closed the hole.
Do not collapse four facts.
- The vendor close is still June. Oracle’s Security Alert for CVE-2026-35273 is dated 10 June 2026, Rev 1. PeopleSoft Enterprise PeopleTools 8.61 and 8.62. Unauthenticated, HTTP, remote code execution. Oracle says PeopleSoft Enterprise Applications customers may also be affected. That advisory has not been superseded by a second CVE in the public record we retrieved.
- CISA already listed this. Catalog freeze this morning is still
2026.09.25, count 1726, same as [yesterday’s SharePoint Daily Top](/posts/2026-09-26-sharepoint-cve-2026-65660-kev/). CVE-2026-35273 was added 12 June, due 15 June. CWE-306. Ransomware-campaign use Known. Forensic triage No. CISA-ADP SSVC on NVD (11 June stamp): exploitation active, automatable yes, technical impact total. There is no new KEV row today. There is a new campaign. - “We blocked /PSEMHUB/” is not patched. Mandiant’s June guidance already said to patch, or disable EMHub, and that WAF body inspection alone was insufficient. Perimeter path blocking was the fallback. UNC6240 adapted to that published fallback. Hunt the encoded variants. Do not treat a string match as the Oracle update.
- The FBI Jobs claim is still a claim. BleepingComputer reports ShinyHunters said they used this WAF bypass against FBI Jobs and still assert a second, unnamed PSEMHUB bug. The FBI has said it is investigating unauthorized activity affecting FBIjobs.gov. It has not confirmed a breach or a data theft. Mandiant’s 26 September post does not name the FBI as a victim. Treat the government-jobs story as REPORTED, not as this campaign’s confirmed patient zero.
This is not a re-run of [yesterday’s SharePoint KEV](/posts/2026-09-26-sharepoint-cve-2026-65660-kev/). SharePoint is a new catalog row. PeopleSoft is an old catalog row with new hands on the keyboard. [WSO2 CVE-2026-5430](/posts/2026-09-25-wso2-cve-2026-5430-kev/) and Adobe Commerce CVE-2026-71362 are due today.
| Fact | Record |
|---|---|
| CVE | CVE-2026-35273 |
| Product | PeopleSoft Enterprise PeopleTools 8.61, 8.62 (Updates Environment Management / PSEMHUB) |
| Vendor advisory | Oracle Security Alert, 10 June 2026, Rev 1 |
| Vendor score | CVSS 3.1 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CWE | CWE-306 (KEV / CISA-ADP) |
| KEV catalog | 2026.09.25, count 1726; this CVE added 12 June |
| Added / due | 12 June / 15 June 2026 (clock already expired) |
| Exploitation | CONFIRMED as KEV since June; CONFIRMED as Mandiant/GTIG September campaign |
| Ransomware use | Known (CISA field). Mandiant describes data-theft extortion, not a named encryptor in this post |
| Named actor | UNC6240 / ShinyHunters — Mandiant tracking, not a court finding |
| OT / process impact | None claimed |
What happened
Mandiant and GTIG’s 26 September post is an update to their 11 June education-sector write-up. Between 27 May and 9 June UNC6240 used CVE-2026-35273 as a zero-day, mostly against higher education. Oracle shipped the out-of-band alert on 10 June. CISA put the CVE on KEV on 12 June. Mandiant had already told operators who could not patch immediately to block external access to /PSEMHUB/*.
The September wave is the adaptation. Mandiant says the actor changed the exploit so string-based WAF rules that look for /PSEMHUB/ miss the request. The documented bypass encodes a single character: /%50SEMHUB/. Mandiant warns the actor can rotate to any percent-encoded, mixed-case, or non-normalized variant, and that blocking must be on the normalized path.
Targeting widened. Mandiant reports web shells on dozens of systems globally in higher education, technology, IT services, healthcare, agriculture, transportation, and government. That is a victim-class statement, not a named-victim list. Agriculture and transportation here are PeopleSoft application estates at organizations in those sectors. They are not confirmed OT or process compromise.
The kill chain Mandiant observed, paraphrased for defenders:
- Verify. Five to 15
POSTrequests to/%50SEMHUB/hubcarrying a serialized Java object. An unpatched server answers with host OS information and does not have to write a file or disrupt the service. Logs can show this burst with no follow-on. That is reconnaissance, not a missed implant. - Exploit. Two methods, both abusing Java deserialization in the PSEMHUB hub servlet. One writes JSP files under
PSEMHUB.war(often in a burst, which Mandiant assesses as hitting every node behind a load balancer). The other is fileless: command output comes back in the HTTP response; on the host,cmd.exeor/bin/shis spawned by the WebLogic Java process. A hunt that only looks for new JSP files misses the second method. - Stay. Dual JSP shells Mandiant names
x.jsp(command execution) andu.jsp/u2.jsp(chunked upload). On Windows, a 5.2 MBPle64.exedropped into the same war directory, signed with an EV certificate issued to Tobias Weihmann Software Development OU via Sectigo, loading a C++ backdoor Mandiant tracks as SIDEEYE. C2 they published:162.219.30.165on TCP 3333 (control) and 3334 (data). Parallel Neo-reGeorgtunnel.jsp/tunnel.jspx. On Linux, legitimate MeshAgent, recently viawinmanage-me.networkon104.219.234.138.
The Hacker News, restating Mandiant, says about a quarter of observed commands ran as root or NT Authority\SYSTEM. The rest ran as PeopleSoft or WebLogic service accounts, which still read psappsrv.cfg, Integration Broker credentials, and the database.
Oracle’s live advisory, retrieved this morning, still says: remotely exploitable without authentication; successful exploitation may result in remote code execution; PeopleTools 8.61 and 8.62; PeopleSoft Enterprise Applications customers may also be affected; earlier, unsupported releases were not tested and are likely affected. NVD last-modified 23 July 2026. No public Oracle revision since Rev 1 on 10 June in the advisory we fetched.
CISA’s catalog did not move overnight. Freeze 2026.09.25 / 1726. WSO2 CVE-2026-5430 and Adobe CVE-2026-71362 remain due 27 September.
RWP is not reproducing serialized Java gadgets, JSP source, or request bodies. Mandiant published enough filenames, paths, and hashes for a hunt. That is the defensive cut.
Why it matters
PeopleSoft is the HR, payroll, campus, and (in many shops) financials plane. An unauthenticated takeover of PeopleTools is not a perimeter curiosity. It is the identity and compensation database plus the WebLogic host it runs on.
Two operational lies will show up in tickets this weekend.
- “We mitigated. The WAF drops /PSEMHUB/.” That was Mandiant’s fallback in June, not Oracle’s fix. A rule that matches the literal path before RFC 3986 decoding is doing what the parser was written to do. UNC6240 changed one character. Mandiant is explicit that other encodings will follow. Normalized-path deny, or take the application off the internet. Then apply the June Security Alert. The WAF is not the patch.
- “KEV due 15 June, so this is a late ticket.” The federal clock expired in June. The access did not. CISA’s ransomware field is already Known. Mandiant’s September post is data-theft extortion tradecraft — steal, then a leak site — and tells operators to prepare for extortion mail. A box that was “in the June exception pile because we had a WAF rule” is now in the Mandiant denominator: unpatched, internet-reachable, and probed.
Forensic triage on this KEV row is No. That is the catalog field from June, not a statement that you should skip the hunt. Mandiant’s own quick guide is the opposite: search logs, inspect PSEMHUB.war, rotate credentials the PeopleSoft service account can read. The patch does not unwind a JSP already written or a MeshAgent already talking.
No public named-victim list in the 26 September Mandiant post. Dozens of systems is CONFIRMED as Mandiant’s count of web-shell deployments they observed, not a global census and not a confirmation of the FBI Jobs story.
A compromised PeopleSoft instance at a manufacturer, a hospital, a railroad, or a farm co-op is IT compromise of an ERP. It is not confirmed OT compromise and is not physical-process impact.
Who / what is affected
| Asset | What to assume | Status |
|---|---|---|
| PeopleTools 8.61 or 8.62, PSEMHUB reachable, June Security Alert not applied | In scope | CONFIRMED vendor / NVD / Mandiant |
| Same trains, alert applied, EMHub disabled or PSEMHUB removed | Vendor close for this CVE | CONFIRMED Oracle + Mandiant guidance |
| PeopleSoft Enterprise Applications on those PeopleTools trains | May also be affected | CONFIRMED Oracle wording |
| Earlier, unsupported PeopleTools | Likely affected, untested | CONFIRMED Oracle; no vendor patch |
Internet-facing PIA with only a literal /PSEMHUB/ WAF or proxy deny | Still reachable via encoded path | CONFIRMED Mandiant |
| Load-balanced WebLogic nodes | Hunt every node | CONFIRMED Mandiant (burst writes) |
| Named victims | None in Mandiant’s September post | UNKNOWN |
| FBI Jobs / FBIjobs.gov | Actor claim of this bypass plus a second bug; FBI investigating | REPORTED; not Mandiant-confirmed |
| Second, unnamed PSEMHUB zero-day | Actor claim only | UNKNOWN / not claimed here |
| OT / ICS / process | Not claimed | No evidence |
| CISA ransomware field | Known | CONFIRMED catalog |
The inventory unit is PeopleTools version, whether EMHub / PSEMHUB is installed, whether it is reachable from untrusted networks (including through a WAF), and whether the June Security Alert is actually applied. That is configuration, not an exploit recipe.
Technical context
RWP is not reproducing gadget chains, JSP bodies, or SIDEEYE unpacking.
What the primary records give defenders:
- Primitive. Missing authentication for a critical function (CWE-306) in PeopleTools Updates Environment Management. Unauthenticated HTTP. Oracle impact: takeover / RCE. CVSS 9.8,
PR:N,UI:N. - Prerequisite for the CVE as scored. An affected PeopleTools 8.61/8.62 stack with the Environment Management Hub (and, in some public technical descriptions, Integration Broker) reachable over HTTP. Mandiant’s observed path is the PSEMHUB hub servlet and Java deserialization.
- Prerequisite for the September bypass, which is not a new CVE. A WAF or reverse proxy that matches
/PSEMHUBon the raw request path, plus a backend that decodes before routing. Mandiant documented/%50SEMHUB/. They tell you to assume other encodings. - Not claimed by Oracle in the alert we retrieved. In-the-wild exploitation (CISA and Mandiant carry that). A second 2026 PSEMHUB CVE. FBI as a victim.
- Follow-on Mandiant observed, not that CISA documented in the KEV row.
x.jsp/u.jsp/u2.jsp,Ple64.exe/ SIDEEYE, Neo-reGeorg, MeshAgent, fileless command execution through the hub POST.
ATT&CK mapping for what Mandiant stated:
- Exploit public-facing application (T1190).
- Server software component / web shell (T1505.003).
- Command and scripting interpreter — Windows (T1059.003) and Unix (T1059.004).
- Unsecured credentials in files (T1552.001).
- Remote access software (T1219) for MeshAgent.
- Proxy (T1090) for Neo-reGeorg / SIDEEYE reverse proxy.
- Exfiltration over alternative protocol (T1048).
Follow-on that is not claimed: a confirmed second zero-day, a named encrypting-ransomware affiliate on this September wave, OT/process impact, or Mandiant confirmation of the FBI Jobs theft.
Threat / exploitation status
| Claim | Status | Basis |
|---|---|---|
| CVE-2026-35273 unauthenticated RCE, PeopleTools 8.61/8.62, CVSS 9.8 | CONFIRMED | Oracle; NVD; CVE.org |
| In KEV since 12 June, due 15 June, CWE-306, ransomware Known, forensic triage No | CONFIRMED | CISA catalog 2026.09.25 |
| Catalog freeze this morning still 2026.09.25 / 1726 | CONFIRMED | CISA JSON retrieved 27 Sep |
| SSVC active / automatable yes / total | CONFIRMED as CISA-ADP, 11 June stamp | NVD |
| June zero-day campaign vs higher education | CONFIRMED as Mandiant June post | GTIG 11 June |
| September WAF-bypass mass exploitation, dozens of web shells, expanded sectors | CONFIRMED as Mandiant/GTIG 26 Sep | Mandiant |
Bypass path /%50SEMHUB/ | CONFIRMED as Mandiant telemetry | Mandiant; BC; THN |
| SIDEEYE / Ple64.exe, Neo-reGeorg, MeshAgent | CONFIRMED as Mandiant malware analysis | Mandiant |
| FBI Jobs breach / 2–3 TB / second PSEMHUB zero-day | REPORTED by the actor via BleepingComputer / THN | Not Mandiant-confirmed; FBI investigating |
| Victim identities | UNKNOWN | No named set in the September Mandiant post |
| OT / physical-process impact | Not claimed | Sector labels are PeopleSoft customers |
High confidence on: CVE ID, Oracle product trains, CVSS 9.8, CWE-306, KEV dates and fields, catalog version and count, Mandiant’s 26 September WAF-bypass description, the /%50SEMHUB/ path, the named web-shell and Ple64.exe artifacts, SIDEEYE C2 IP and ports, MeshAgent domain, and that this is not a new KEV add. Moderate confidence that unpatched, internet-reachable PSEMHUB behind a literal-path WAF is the dominant remaining condition (that is the population Mandiant says they hit; no public census of remaining exposure). Low confidence on CISA’s unpublished original KEV evidence from June, on any named victim, on whether a second PSEMHUB bug exists, and on the FBI Jobs claim.
What defenders should do
- Inventory PeopleTools, not “we have a WAF.” Version 8.61 / 8.62, whether EMHub is installed, whether PSEMHUB or the Integration Broker listening connector is reachable from untrusted networks, and whether Oracle’s 10 June Security Alert is applied. Unsupported earlier trains: Oracle says likely affected and untested — treat as exposed until upgraded. Record internet exposure even though this KEV due date is already past.
- Patch, then disable the unused admin surface. Apply the Oracle Security Alert for CVE-2026-35273. Mandiant (and Oracle’s alert guidance as Mandiant restates it): disable EMHub in multi-server configurations, or remove the PSEMHUB application in single-server configurations. Mandiant notes EMHub and the Integration Broker connector are administrative / system-to-system; restricting them from the public internet is non-breaking for ordinary PIA user sessions. A WAF string match is not this step.
- Hunt the encoded path and the fileless path. Search PIA WebLogic access logs for
/PSEMHUB/and percent-encoded variants (/%50SEMHUB/and any other encoding of the same path), especially externalPOSTto/huband requests to unexpected.jsp/.jspxunder PSEMHUB or PORTAL. On hosts, alert oncmd.exe,/bin/sh, orbashspawned by the WebLogic Java process. Inspect<PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/for files that are not product:x.jsp,u.jsp,u2.jsp,tunnel.jsp,tunnel.jspx,Ple64.exe. Check every load-balanced node. If you find a web shell, treat the host as compromised; the June patch does not remove it.
- Use Mandiant’s published indicators as hunt material, not as a complete blocklist.
| Indicator | Role |
|---|---|
| 5.199.162.157 | Attack controller / scanner / HTTP callback |
| 104.219.234.138 | Staging / remote management |
| 162.219.30.165 | SIDEEYE C2 (TCP 3333 / 3334) |
| winmanage-me.network | MeshCentral infrastructure |
| SHA-256 3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3 | Ple64.exe |
| SHA-256 48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494 | x.jsp (Mandiant: hashes vary with newlines) |
| SHA-256 2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7 | u.jsp |
Rotate credentials the PeopleSoft service account can read: database strings in psappsrv.cfg, Integration Broker, cloud credentials on the web tier. Review DB audit logs for bulk HR / payroll / student exports. Look for large .tar / .zst archives and tar / zstd / sshpass / rsync spawned by the app account. Unexpected MeshCentral agents.
- Prepare for extortion mail. Mandiant’s pattern for UNC6240 is steal-then-leak, not a named encryptor in this post. CISA’s KEV field is already Known. Those are adjacent, not identical. Watch the leak site; do not wait for a ransom note to start the hunt.
- Sequence the rest of this window. Due today: [WSO2 CVE-2026-5430](/posts/2026-09-25-wso2-cve-2026-5430-kev/) and Adobe Commerce CVE-2026-71362. Due tomorrow: [SharePoint CVE-2026-65660](/posts/2026-09-26-sharepoint-cve-2026-65660-kev/), WordPress CVE-2026-87902, MikroTik CVE-2026-67279. Citrix NetScaler “two unpatched RCE zero-days” (watchTowr, 26 September, no vendor confirmation, no CVE in the public record we retrieved) is sequenced below — do not skip an inventory of internet-facing ADC/Gateway, but do not treat a rumor as a bulletin.
This is not an exploitation guide. Use Oracle’s Security Alert and Mandiant’s hunt list.
RWP assessment
Score 8.7. Primary-source campaign expansion against an unauthenticated CVSS 9.8 ERP RCE that many estates closed with a WAF string. Mandiant, 26 September. That is the highest-leverage new development since [yesterday’s SharePoint KEV](/posts/2026-09-26-sharepoint-cve-2026-65660-kev/).
It outranks a second day on SharePoint CVE-2026-65660 because yesterday already shipped the catalog row, the Microsoft recast, and the Monday due date; there is no new freeze this morning. It outranks CVE-2026-5430 and CVE-2026-71362 (due today) because those deadlines are clocks on stories already assessed 24–25 September. It outranks watchTowr’s 26 September Citrix NetScaler rumor (two unpatched RCEs, The Hacker News 27 September, Citrix silent, no CVE, no patch, no IOC) because evidence quality is poor even though the operational blast radius if confirmed would be large. Doctrine: the highest hypothetical score does not win a thin source. It outranks Roundcube CVE-2026-48842 (Canadian Centre, 21 September, virtuser_query, not KEV, plugin off by default). It outranks Kiteworks’ precautionary shutdown (still no CVE).
The June PeopleSoft zero-day was sequenced in [July’s ShinyHunters SaaS note](/posts/2026-07-13-shinyhunters-saas-oauth/) as a related brand, different door, and the FBI Jobs claim sat at 6.4 on 23–24 September as REPORTED only. Mandiant’s WAF-bypass post is the material development: new technique, new tooling, expanded sectors, defender-actionable artifacts. It is not a second CVE.
The failure mode to sand down is “the WAF caught PSEMHUB” and its twin, “June’s KEV clock already rang.” If PSEMHUB still answers on a decoded path, you are in Mandiant’s denominator.
What we are watching
- Whether Oracle revises the 10 June alert, names exploitation, or assigns a second PSEMHUB CVE.
- Whether CISA flips forensic triage or adds a new row; catalog is still
2026.09.25/ 1726. - Whether Mandiant, the FBI, or a victim names FBI Jobs as this bypass — or as something else.
- Sectigo revocation of the Tobias Weihmann EV certificate on
Ple64.exe. - Whether ransomware-Known in KEV gets a named encryptor on this September wave, or stays steal-then-leak.
- Citrix confirmation or denial of watchTowr’s unpatched NetScaler RCE rumor.
- Any attempt to treat PeopleSoft at an industrial company as OT impact without process evidence.
Sources
- Mandiant / GTIG — ShinyHunters renewed mass exploitation of Oracle PeopleSoft (26 September 2026)
- Mandiant / GTIG — June 2026 education-sector campaign
- Oracle — Security Alert Advisory CVE-2026-35273
- NVD — CVE-2026-35273
- CVE.org — CVE-2026-35273
- CISA KEV JSON feed
- CISA Known Exploited Vulnerabilities Catalog
- CISA — BOD 26-04
- BleepingComputer — ShinyHunters uses WAF bypass trick (26 September 2026)
- The Hacker News — Attackers bypass WAFs to exploit Oracle PeopleSoft (26 September 2026)
- Reuters — ShinyHunters expanded attacks on Oracle PeopleSoft, Google says (26 September 2026)
- CSA Singapore — AL-2026-072
- [RWP Daily Top, 26 September 2026 — SharePoint CVE-2026-65660](/posts/2026-09-26-sharepoint-cve-2026-65660-kev/)
- [RWP Daily Top, 25 September 2026 — WSO2 CVE-2026-5430](/posts/2026-09-25-wso2-cve-2026-5430-kev/)
- [RWP, 13 July 2026 — ShinyHunters SaaS OAuth](/posts/2026-07-13-shinyhunters-saas-oauth/)
Sources
- Mandiant / GTIG — ShinyHunters renewed mass exploitation of Oracle PeopleSoft
- Oracle — Security Alert Advisory CVE-2026-35273
- NVD — CVE-2026-35273
- CVE — CVE-2026-35273
- CISA — KEV JSON feed catalog 2026.09.25
- CISA — Known Exploited Vulnerabilities Catalog
- CISA — BOD 26-04
- BleepingComputer — ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
- The Hacker News — Attackers bypass WAFs to exploit Oracle PeopleSoft flaw
- Reuters — ShinyHunters expanded attacks on Oracle PeopleSoft, Google says
- Mandiant / GTIG — June 2026 PeopleSoft education-sector campaign
- CSA Singapore — AL-2026-072 CVE-2026-35273