Daily Top · Threats / Oracle

The PeopleSoft WAF matched /PSEMHUB/. UNC6240 asked for /%50SEMHUB/.

Mandiant and GTIG on 26 September. CVE-2026-35273 is the June N-day. The literal-path rule is not the patch.

RWP Ventures · 2026-09-27 · event 2026-09-26 · 16 min read · priority 8.7

Bottom line up front

CONFIRMED Mandiant and Google Threat Intelligence Group published 26 September 2026 that UNC6240 (publicly ShinyHunters) resumed mass exploitation of CVE-2026-35273 against Oracle PeopleSoft. The June zero-day is now an N-day. The new fact is not a new CVE. It is a one-character URL encoding that walks past the WAF rule a lot of operators used instead of the patch.

The encoded path Mandiant documented is /%50SEMHUB/ in place of /PSEMHUB/. %50 is the letter P. Many WAF and reverse-proxy rules match the literal string before decoding. WebLogic then decodes the path and routes it to the Environment Management Hub servlet. Mandiant’s sentence: operators may have believed the WAF had closed the hole.

Do not collapse four facts.

  1. The vendor close is still June. Oracle’s Security Alert for CVE-2026-35273 is dated 10 June 2026, Rev 1. PeopleSoft Enterprise PeopleTools 8.61 and 8.62. Unauthenticated, HTTP, remote code execution. Oracle says PeopleSoft Enterprise Applications customers may also be affected. That advisory has not been superseded by a second CVE in the public record we retrieved.
  2. CISA already listed this. Catalog freeze this morning is still 2026.09.25, count 1726, same as [yesterday’s SharePoint Daily Top](/posts/2026-09-26-sharepoint-cve-2026-65660-kev/). CVE-2026-35273 was added 12 June, due 15 June. CWE-306. Ransomware-campaign use Known. Forensic triage No. CISA-ADP SSVC on NVD (11 June stamp): exploitation active, automatable yes, technical impact total. There is no new KEV row today. There is a new campaign.
  3. “We blocked /PSEMHUB/” is not patched. Mandiant’s June guidance already said to patch, or disable EMHub, and that WAF body inspection alone was insufficient. Perimeter path blocking was the fallback. UNC6240 adapted to that published fallback. Hunt the encoded variants. Do not treat a string match as the Oracle update.
  4. The FBI Jobs claim is still a claim. BleepingComputer reports ShinyHunters said they used this WAF bypass against FBI Jobs and still assert a second, unnamed PSEMHUB bug. The FBI has said it is investigating unauthorized activity affecting FBIjobs.gov. It has not confirmed a breach or a data theft. Mandiant’s 26 September post does not name the FBI as a victim. Treat the government-jobs story as REPORTED, not as this campaign’s confirmed patient zero.

This is not a re-run of [yesterday’s SharePoint KEV](/posts/2026-09-26-sharepoint-cve-2026-65660-kev/). SharePoint is a new catalog row. PeopleSoft is an old catalog row with new hands on the keyboard. [WSO2 CVE-2026-5430](/posts/2026-09-25-wso2-cve-2026-5430-kev/) and Adobe Commerce CVE-2026-71362 are due today.

FactRecord
CVECVE-2026-35273
ProductPeopleSoft Enterprise PeopleTools 8.61, 8.62 (Updates Environment Management / PSEMHUB)
Vendor advisoryOracle Security Alert, 10 June 2026, Rev 1
Vendor scoreCVSS 3.1 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWECWE-306 (KEV / CISA-ADP)
KEV catalog2026.09.25, count 1726; this CVE added 12 June
Added / due12 June / 15 June 2026 (clock already expired)
ExploitationCONFIRMED as KEV since June; CONFIRMED as Mandiant/GTIG September campaign
Ransomware useKnown (CISA field). Mandiant describes data-theft extortion, not a named encryptor in this post
Named actorUNC6240 / ShinyHunters — Mandiant tracking, not a court finding
OT / process impactNone claimed

What happened

Mandiant and GTIG’s 26 September post is an update to their 11 June education-sector write-up. Between 27 May and 9 June UNC6240 used CVE-2026-35273 as a zero-day, mostly against higher education. Oracle shipped the out-of-band alert on 10 June. CISA put the CVE on KEV on 12 June. Mandiant had already told operators who could not patch immediately to block external access to /PSEMHUB/*.

The September wave is the adaptation. Mandiant says the actor changed the exploit so string-based WAF rules that look for /PSEMHUB/ miss the request. The documented bypass encodes a single character: /%50SEMHUB/. Mandiant warns the actor can rotate to any percent-encoded, mixed-case, or non-normalized variant, and that blocking must be on the normalized path.

Targeting widened. Mandiant reports web shells on dozens of systems globally in higher education, technology, IT services, healthcare, agriculture, transportation, and government. That is a victim-class statement, not a named-victim list. Agriculture and transportation here are PeopleSoft application estates at organizations in those sectors. They are not confirmed OT or process compromise.

The kill chain Mandiant observed, paraphrased for defenders:

The Hacker News, restating Mandiant, says about a quarter of observed commands ran as root or NT Authority\SYSTEM. The rest ran as PeopleSoft or WebLogic service accounts, which still read psappsrv.cfg, Integration Broker credentials, and the database.

Oracle’s live advisory, retrieved this morning, still says: remotely exploitable without authentication; successful exploitation may result in remote code execution; PeopleTools 8.61 and 8.62; PeopleSoft Enterprise Applications customers may also be affected; earlier, unsupported releases were not tested and are likely affected. NVD last-modified 23 July 2026. No public Oracle revision since Rev 1 on 10 June in the advisory we fetched.

CISA’s catalog did not move overnight. Freeze 2026.09.25 / 1726. WSO2 CVE-2026-5430 and Adobe CVE-2026-71362 remain due 27 September.

RWP is not reproducing serialized Java gadgets, JSP source, or request bodies. Mandiant published enough filenames, paths, and hashes for a hunt. That is the defensive cut.

Why it matters

PeopleSoft is the HR, payroll, campus, and (in many shops) financials plane. An unauthenticated takeover of PeopleTools is not a perimeter curiosity. It is the identity and compensation database plus the WebLogic host it runs on.

Two operational lies will show up in tickets this weekend.

  1. “We mitigated. The WAF drops /PSEMHUB/.” That was Mandiant’s fallback in June, not Oracle’s fix. A rule that matches the literal path before RFC 3986 decoding is doing what the parser was written to do. UNC6240 changed one character. Mandiant is explicit that other encodings will follow. Normalized-path deny, or take the application off the internet. Then apply the June Security Alert. The WAF is not the patch.
  2. “KEV due 15 June, so this is a late ticket.” The federal clock expired in June. The access did not. CISA’s ransomware field is already Known. Mandiant’s September post is data-theft extortion tradecraft — steal, then a leak site — and tells operators to prepare for extortion mail. A box that was “in the June exception pile because we had a WAF rule” is now in the Mandiant denominator: unpatched, internet-reachable, and probed.

Forensic triage on this KEV row is No. That is the catalog field from June, not a statement that you should skip the hunt. Mandiant’s own quick guide is the opposite: search logs, inspect PSEMHUB.war, rotate credentials the PeopleSoft service account can read. The patch does not unwind a JSP already written or a MeshAgent already talking.

No public named-victim list in the 26 September Mandiant post. Dozens of systems is CONFIRMED as Mandiant’s count of web-shell deployments they observed, not a global census and not a confirmation of the FBI Jobs story.

A compromised PeopleSoft instance at a manufacturer, a hospital, a railroad, or a farm co-op is IT compromise of an ERP. It is not confirmed OT compromise and is not physical-process impact.

Who / what is affected

AssetWhat to assumeStatus
PeopleTools 8.61 or 8.62, PSEMHUB reachable, June Security Alert not appliedIn scopeCONFIRMED vendor / NVD / Mandiant
Same trains, alert applied, EMHub disabled or PSEMHUB removedVendor close for this CVECONFIRMED Oracle + Mandiant guidance
PeopleSoft Enterprise Applications on those PeopleTools trainsMay also be affectedCONFIRMED Oracle wording
Earlier, unsupported PeopleToolsLikely affected, untestedCONFIRMED Oracle; no vendor patch
Internet-facing PIA with only a literal /PSEMHUB/ WAF or proxy denyStill reachable via encoded pathCONFIRMED Mandiant
Load-balanced WebLogic nodesHunt every nodeCONFIRMED Mandiant (burst writes)
Named victimsNone in Mandiant’s September postUNKNOWN
FBI Jobs / FBIjobs.govActor claim of this bypass plus a second bug; FBI investigatingREPORTED; not Mandiant-confirmed
Second, unnamed PSEMHUB zero-dayActor claim onlyUNKNOWN / not claimed here
OT / ICS / processNot claimedNo evidence
CISA ransomware fieldKnownCONFIRMED catalog

The inventory unit is PeopleTools version, whether EMHub / PSEMHUB is installed, whether it is reachable from untrusted networks (including through a WAF), and whether the June Security Alert is actually applied. That is configuration, not an exploit recipe.

Technical context

RWP is not reproducing gadget chains, JSP bodies, or SIDEEYE unpacking.

What the primary records give defenders:

ATT&CK mapping for what Mandiant stated:

Follow-on that is not claimed: a confirmed second zero-day, a named encrypting-ransomware affiliate on this September wave, OT/process impact, or Mandiant confirmation of the FBI Jobs theft.

Threat / exploitation status

ClaimStatusBasis
CVE-2026-35273 unauthenticated RCE, PeopleTools 8.61/8.62, CVSS 9.8CONFIRMEDOracle; NVD; CVE.org
In KEV since 12 June, due 15 June, CWE-306, ransomware Known, forensic triage NoCONFIRMEDCISA catalog 2026.09.25
Catalog freeze this morning still 2026.09.25 / 1726CONFIRMEDCISA JSON retrieved 27 Sep
SSVC active / automatable yes / totalCONFIRMED as CISA-ADP, 11 June stampNVD
June zero-day campaign vs higher educationCONFIRMED as Mandiant June postGTIG 11 June
September WAF-bypass mass exploitation, dozens of web shells, expanded sectorsCONFIRMED as Mandiant/GTIG 26 SepMandiant
Bypass path /%50SEMHUB/CONFIRMED as Mandiant telemetryMandiant; BC; THN
SIDEEYE / Ple64.exe, Neo-reGeorg, MeshAgentCONFIRMED as Mandiant malware analysisMandiant
FBI Jobs breach / 2–3 TB / second PSEMHUB zero-dayREPORTED by the actor via BleepingComputer / THNNot Mandiant-confirmed; FBI investigating
Victim identitiesUNKNOWNNo named set in the September Mandiant post
OT / physical-process impactNot claimedSector labels are PeopleSoft customers

High confidence on: CVE ID, Oracle product trains, CVSS 9.8, CWE-306, KEV dates and fields, catalog version and count, Mandiant’s 26 September WAF-bypass description, the /%50SEMHUB/ path, the named web-shell and Ple64.exe artifacts, SIDEEYE C2 IP and ports, MeshAgent domain, and that this is not a new KEV add. Moderate confidence that unpatched, internet-reachable PSEMHUB behind a literal-path WAF is the dominant remaining condition (that is the population Mandiant says they hit; no public census of remaining exposure). Low confidence on CISA’s unpublished original KEV evidence from June, on any named victim, on whether a second PSEMHUB bug exists, and on the FBI Jobs claim.

What defenders should do

  1. Inventory PeopleTools, not “we have a WAF.” Version 8.61 / 8.62, whether EMHub is installed, whether PSEMHUB or the Integration Broker listening connector is reachable from untrusted networks, and whether Oracle’s 10 June Security Alert is applied. Unsupported earlier trains: Oracle says likely affected and untested — treat as exposed until upgraded. Record internet exposure even though this KEV due date is already past.
  1. Patch, then disable the unused admin surface. Apply the Oracle Security Alert for CVE-2026-35273. Mandiant (and Oracle’s alert guidance as Mandiant restates it): disable EMHub in multi-server configurations, or remove the PSEMHUB application in single-server configurations. Mandiant notes EMHub and the Integration Broker connector are administrative / system-to-system; restricting them from the public internet is non-breaking for ordinary PIA user sessions. A WAF string match is not this step.
  1. Hunt the encoded path and the fileless path. Search PIA WebLogic access logs for /PSEMHUB/ and percent-encoded variants (/%50SEMHUB/ and any other encoding of the same path), especially external POST to /hub and requests to unexpected .jsp / .jspx under PSEMHUB or PORTAL. On hosts, alert on cmd.exe, /bin/sh, or bash spawned by the WebLogic Java process. Inspect <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/ for files that are not product: x.jsp, u.jsp, u2.jsp, tunnel.jsp, tunnel.jspx, Ple64.exe. Check every load-balanced node. If you find a web shell, treat the host as compromised; the June patch does not remove it.
  1. Use Mandiant’s published indicators as hunt material, not as a complete blocklist.

| Indicator | Role |

|---|---|

| 5.199.162.157 | Attack controller / scanner / HTTP callback |

| 104.219.234.138 | Staging / remote management |

| 162.219.30.165 | SIDEEYE C2 (TCP 3333 / 3334) |

| winmanage-me.network | MeshCentral infrastructure |

| SHA-256 3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3 | Ple64.exe |

| SHA-256 48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494 | x.jsp (Mandiant: hashes vary with newlines) |

| SHA-256 2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7 | u.jsp |

Rotate credentials the PeopleSoft service account can read: database strings in psappsrv.cfg, Integration Broker, cloud credentials on the web tier. Review DB audit logs for bulk HR / payroll / student exports. Look for large .tar / .zst archives and tar / zstd / sshpass / rsync spawned by the app account. Unexpected MeshCentral agents.

  1. Prepare for extortion mail. Mandiant’s pattern for UNC6240 is steal-then-leak, not a named encryptor in this post. CISA’s KEV field is already Known. Those are adjacent, not identical. Watch the leak site; do not wait for a ransom note to start the hunt.
  1. Sequence the rest of this window. Due today: [WSO2 CVE-2026-5430](/posts/2026-09-25-wso2-cve-2026-5430-kev/) and Adobe Commerce CVE-2026-71362. Due tomorrow: [SharePoint CVE-2026-65660](/posts/2026-09-26-sharepoint-cve-2026-65660-kev/), WordPress CVE-2026-87902, MikroTik CVE-2026-67279. Citrix NetScaler “two unpatched RCE zero-days” (watchTowr, 26 September, no vendor confirmation, no CVE in the public record we retrieved) is sequenced below — do not skip an inventory of internet-facing ADC/Gateway, but do not treat a rumor as a bulletin.

This is not an exploitation guide. Use Oracle’s Security Alert and Mandiant’s hunt list.

RWP assessment

Score 8.7. Primary-source campaign expansion against an unauthenticated CVSS 9.8 ERP RCE that many estates closed with a WAF string. Mandiant, 26 September. That is the highest-leverage new development since [yesterday’s SharePoint KEV](/posts/2026-09-26-sharepoint-cve-2026-65660-kev/).

It outranks a second day on SharePoint CVE-2026-65660 because yesterday already shipped the catalog row, the Microsoft recast, and the Monday due date; there is no new freeze this morning. It outranks CVE-2026-5430 and CVE-2026-71362 (due today) because those deadlines are clocks on stories already assessed 24–25 September. It outranks watchTowr’s 26 September Citrix NetScaler rumor (two unpatched RCEs, The Hacker News 27 September, Citrix silent, no CVE, no patch, no IOC) because evidence quality is poor even though the operational blast radius if confirmed would be large. Doctrine: the highest hypothetical score does not win a thin source. It outranks Roundcube CVE-2026-48842 (Canadian Centre, 21 September, virtuser_query, not KEV, plugin off by default). It outranks Kiteworks’ precautionary shutdown (still no CVE).

The June PeopleSoft zero-day was sequenced in [July’s ShinyHunters SaaS note](/posts/2026-07-13-shinyhunters-saas-oauth/) as a related brand, different door, and the FBI Jobs claim sat at 6.4 on 23–24 September as REPORTED only. Mandiant’s WAF-bypass post is the material development: new technique, new tooling, expanded sectors, defender-actionable artifacts. It is not a second CVE.

The failure mode to sand down is “the WAF caught PSEMHUB” and its twin, “June’s KEV clock already rang.” If PSEMHUB still answers on a decoded path, you are in Mandiant’s denominator.

What we are watching

Sources

Sources

  1. Mandiant / GTIG — ShinyHunters renewed mass exploitation of Oracle PeopleSoft
  2. Oracle — Security Alert Advisory CVE-2026-35273
  3. NVD — CVE-2026-35273
  4. CVE — CVE-2026-35273
  5. CISA — KEV JSON feed catalog 2026.09.25
  6. CISA — Known Exploited Vulnerabilities Catalog
  7. CISA — BOD 26-04
  8. BleepingComputer — ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
  9. The Hacker News — Attackers bypass WAFs to exploit Oracle PeopleSoft flaw
  10. Reuters — ShinyHunters expanded attacks on Oracle PeopleSoft, Google says
  11. Mandiant / GTIG — June 2026 PeopleSoft education-sector campaign
  12. CSA Singapore — AL-2026-072 CVE-2026-35273