ShinyHunters Bypass WAFs to Exploit Oracle PeopleSoft Flaw, Deploy Web Shells

SentiSense · Published · Updated

Google's Mandiant and Threat Intelligence Group say the ShinyHunters group has launched a renewed mass-exploitation campaign against CVE-2026-35273, a CVSS 9.8 unauthenticated remote code execution flaw in [ORCL](/stocks/ORCL) PeopleSoft. The September 2026 wave follows a May to June zero-day campaign that Oracle addressed in a June 10 Security Alert, and it evades web application firewalls by URL-encoding one character of the request path before deploying web shells on dozens of systems. Mandiant has notified over 100 organizations whose IP addresses matched vulnerable endpoints.

Google has warned that the ShinyHunters group expanded attacks on Oracle's PeopleSoft. According to Mandiant and Google Threat Intelligence Group, the group is running a renewed mass-exploitation campaign in September 2026 against CVE-2026-35273, a CVSS 9.8 unauthenticated remote code execution flaw in the PeopleSoft Environment Management Hub (PSEMHUB) from ORCL.

This is a second wave. The first zero-day exploitation ran from May 27 to June 9, 2026, predominantly against academic institutions, and Oracle released a Security Alert on June 10, 2026. The renewed campaign targets web application firewall rules rather than an unpatched hole: attackers request /%50SEMHUB/ in place of /PSEMHUB/, so WAF and proxy rules that match the literal string miss the request while WebLogic decodes the path and serves the application normally.

Once inside, the attackers deployed web shells, including x.jsp and u.jsp, on dozens of systems globally, and Mandiant also documented u2.jsp and Neo-reGeorg tunneling shells. About a quarter of the threat actor's commands were executed as root or NT Authority\SYSTEM. Targeted sectors include higher education, technology, IT services, healthcare, agriculture, transportation and government, and Mandiant has notified over 100 organizations whose IP addresses matched vulnerable endpoints.

What to watch: whether PeopleSoft customers have applied Oracle's June 10 fix rather than relying on WAF rules, further indicators of compromise from Mandiant, and any confirmed data theft, which the current reporting does not establish.

Related Stocks

Powered by SentiSense - Intelligent Market Analysis