HomeSecurityOracle PeopleSoft: Attacks bypass WAFs and deploy web shells

Oracle PeopleSoft: Attacks bypass WAFs and deploy web shells

A new wave of cyberattacks is targeting Oracle PeopleSoft systems worldwide, exploiting a critical vulnerability that allows remote code execution without authentication. According to The Hacker News, Google has issued a warning about a massive exploitation of the vulnerability CVE-2026-35273 (CVSS score: 9.8 ), which affects Oracle PeopleSoft's Environment Management Hub (PSEMHUB) . The activity is attributed to the UNC6240 group , which is associated with ShinyHunters , and has already compromised dozens of organizations across multiple industries.

Oracle PeopleSoft vulnerability CVE-2026-35273 WAF bypass web shell attack

The CVE-2026-35273 was initially identified as a zero-day in attacks against academic institutions. During these early attacks, attackers performed reconnaissance, installed remote access software such as the MeshCentral agent, moved laterally via SSH, and stole data. Mandiant, a subsidiary of Google, had at that time notified more than 100 organizations whose IP addresses corresponded to vulnerable endpoints, the majority of which were located in the US.

The new wave of attacks differs significantly from the previous one: UNC6240 modified exploit to bypass WAFs (Web Application Firewalls) that blocked the vulnerable endpoint /PSEMHUB/. The technique is simple but extremely effective: attackers use URL encoding for a single character in the request path, requesting /%50SEMHUB/ instead of /PSEMHUB/. Many WAF rules and reverse proxies check the path before URL decoding, while the PeopleSoft decodes the request and routes it to the vulnerable servlet.

See also: ShinyHunters: Claims FBI breach via Oracle PeopleSoft zero-day

How attackers exploit Oracle PeopleSoft

The UNC6240 attack chain is multi-layered and sophisticated. First, attackers target vulnerable Oracle PeopleSoft systems by sending POST requests to /%50SEMHUB/hub containing a serialized Java object. They then exploit Java deserialization in the PSEMHUB servlet to install web shells and achieve fileless command execution .

Specifically, two JSP web shells are installed in the PSEMHUB.war directory to minimize WAF detection after exploitation. x.jsp allows for cross-platform command execution, while u.jsp allows for chunked file uploads and command execution via cmd.exe . The use of u.jsp also extends to the download of a legitimate, signed but modified installer named Ple64.exe , which loads SIDEEYE , a backdoor written in C++ , into memory .

Oracle PeopleSoft - SecNews.gr

SIDEEYE communicates with an external server ( 162.219.30 [.]165 ) via TCP and provides extensive capabilities: stealing credentials from browsers and desktop applications, process and file management, interactive reverse shell and reverse proxy capabilities. In addition, the team uses the open source tool Neo-reGeorg for tunneling , while on Linux systems it installs the legitimate tool RMM MeshAgent for persistent access.

Objectives and impact of the campaign against Oracle PeopleSoft

The latest Oracle PeopleSoft a wide range of industries: higher education, technology, IT services, healthcare, agriculture, transportation, and government. It is worth noting that UNC6240 has installed web shells on dozens of systems, while about a quarter of the commands executed were executed with root or NT Authority\SYSTEM, providing full control of the operating system. The remaining commands were executed under PeopleSoft or WebLogic.

See also: ShinyHunters: Massive attacks against Oracle PeopleSoft for data theft

The profile of UNC6240 is particularly concerning: the group has an established pattern of extortion through data theft. Given that Oracle PeopleSoft is widely used for managing human resources, payroll, and student records, the theft of such data could have devastating consequences for victim organizations. The connection to ShinyHunters, a group known for large-scale data breaches, heightens concerns about the potential impact.

In the European and Greek context, the threat is equally serious. Many universities, hospitals and public organizations use ERP such as Oracle PeopleSoft for critical functions. A successful attack can lead to the leakage of sensitive personal data, a violation of GDPR and serious financial penalties. Organizations using Oracle PeopleSoft must address this threat as an urgent priority.

WooCommerce Wholesale Lead Capture PHP web shell vulnerability CVE-2026-27540

Protection measures for Oracle PeopleSoft systems

Mandiant and Google have issued specific guidance to address the threat. First and foremost, organizations should immediately apply the patch updates for CVE-2026-35273 . It is also recommended to disable the Environment Management Hub (EMHub) service in multi-server configurations or completely remove the PSEMHUB application in single-server configurations.

To identify a potential breach, security teams should search WebLogic access logs for requests to /PSEMHUB/ and any percent-encoded variations. Additionally, the PSEMHUB.war directory should be checked for JSP web shells and other malicious files. Rotating credentials that are readable by the PeopleSoft service account is also critical.

See also: Oracle WebLogic CPU July 2026: 5 critical RCEs — deserialization in T3/IIOP/HTTP/SOAP

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Additionally, organizations should look for large archive files in temporary or web-accessible directories. Finally, monitoring outbound traffic from Oracle PeopleSoft servers can reveal suspicious communications with external control servers.

CISA KEV vulnerability list reverse shells crypto miners 2026

This case highlights a major weakness in many organizations’ security architecture: overreliance on WAFs as the sole line of defense. The URL encoding has been known for years, but it is still effective against many WAF implementations. Organizations should adopt a defense-in-, combining patching, network segmentation, monitoring, and anomaly detection to protect critical systems like Oracle PeopleSoft.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS