Vulnerabilities
ShinyHunters is back on PeopleSoft with a WAF bypass
UNC6240 is exploiting Oracle PeopleSoft CVE-2026-35273 again with one encoded letter. The fix, the web shell paths, SIDEEYE and MeshAgent IOCs, and what to rotate.
Google's Mandiant and Threat Intelligence Group (GTIG) reported on September 25 that the extortion group ShinyHunters, tracked as UNC6240, has started a second mass exploitation run against Oracle PeopleSoft. The flaw is CVE-2026-35273 (CVSS 9.8), the same one the group used as a zero-day between May 27 and June 9. This time it placed web shells on dozens of systems worldwide, in higher education, technology, IT services, healthcare, agriculture, transportation and government.
If you run PeopleSoft PeopleTools 8.61 or 8.62 and put a web application firewall (WAF) rule in front of /PSEMHUB/ instead of patching, assume that rule no longer protects you. The attackers now request the path with one letter percent-encoded, and many WAF and proxy rules match the raw string before decoding it. Earlier, unsupported PeopleTools releases may also be affected.
How it works
The Environment Management Hub (EMHub) is a PeopleTools component that collects configuration data from the servers in a PeopleSoft installation. It is an administrative, server-to-server service, served by the same WebLogic web tier as the PeopleSoft Internet Architecture (PIA) pages that users log in to. Its endpoint, /PSEMHUB/hub, accepts requests over HTTP with no authentication, and Oracle describes the result of CVE-2026-35273 as remote code execution by an unauthenticated attacker.
Mandiant's write-up shows how the exploit is delivered. The attacker sends a POST to /PSEMHUB/hub whose body is a serialized Java object. Before a real attack, targets typically got five to 15 of these probes. An unpatched server answers with its host operating system and writes nothing to disk, so the scan leaves little trace beyond access log lines.
The September change is the path. Instead of /PSEMHUB/, the requests go to /%50SEMHUB/, where %50 is the encoded form of the letter P. A WAF rule that looks for the literal text /PSEMHUB does not match. WebLogic decodes the path and hands the request to the vulnerable application as normal. Mandiant advises assuming any encoded, mixed-case or otherwise non-normalized variant will be tried, and blocking on the decoded path.
What attackers are doing
The first wave, from May 27 to June 9, hit more than 100 organizations, most of them in the United States, and 68 percent of them in higher education. After getting in, UNC6240 installed MeshCentral remote management agents named to look like Azure tooling and pointed at azurenetfiles.net, then stole data and published some of it on its leak site on June 9. Oracle issued an out-of-band Security Alert with a patch on June 10, and CISA added the CVE to its Known Exploited Vulnerabilities (KEV) catalog on June 12.
In the September intrusions, exploitation took two forms. Some requests returned command output directly in the HTTP response with no file written. Others dropped JSP web shells into the EMHub application directory, <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/:
x.jspruns hex-encoded commands passed in thecparameter, throughcmd.exeon Windows or/bin/shon Linux. It builds the/bin/shstring from character codes to dodge simple signatures.u.jsp(and au2.jspvariant) writes Base64 file chunks of about 150 KB to disk and runs commands. That gets larger tools past request size limits.tunnel.jspandtunnel.jspxare Neo-reGeorg, an open-source toolkit that carries SOCKS5 proxy traffic inside ordinary HTTP and HTTPS requests to the web server. The attacker gets a route into the internal network that looks like web traffic to your firewall.
On Windows servers the group uploaded Ple64.exe, a 5.2 MB trojanized installer for the Light Alloy media player, signed with a valid Extended Validation certificate. It unpacks a VMProtect-protected loader, which runs the SIDEEYE backdoor in memory. SIDEEYE steals saved browser and application credentials, manages files and processes, opens a reverse shell and proxies traffic. It talks raw TCP to 162.219.30.165, port 3333 for control and 3334 for data.
On Linux the group ran MeshAgent, the agent for the legitimate MeshCentral platform, from /tmp under the PeopleSoft service account, managed through winmanage-me.network. About a quarter of the commands Mandiant saw ran as root or NT Authority\SYSTEM. The rest ran as the PeopleSoft or WebLogic service account, which can still read psappsrv.cfg and its database connection details.
What to do
- Patch. Apply the patch from Oracle's June 10 Security Alert for CVE-2026-35273 to every PeopleTools 8.61 and 8.62 environment, including test and training instances that face the internet. If you are on an older, unsupported PeopleTools release, plan the upgrade now, since you may be exposed with no fix.
- If you cannot patch today, follow Oracle's workaround. Disable the EMHub service in multi-server configurations, or remove the PSEMHUB application in single-server ones. At the perimeter, block external access to
/PSEMHUB/*and/PSIGW/HttpListeningConnector(the Integration Broker listener), and make sure the rule matches after URL decoding and case folding. Both are system-to-system components, so cutting them off from the internet does not break normal PIA user sessions. - Search the access logs. In the PIA WebLogic access log (usually
<PS_CFG_HOME>/webserv/<domain>/servers/PIA/logs/PIA_access.log), look forPOSTrequests to/huband for any.jspor.jspxrequest under PSEMHUB or PORTAL from outside addresses.grep -iE 'semhub' PIA_access.log*catches both the plain and the%50form, but decode the logs before trusting a clean result, because other letters can be encoded too. Go back to May 27. - Inspect the web tier. List files in
PSEMHUB.war/andPORTAL.war/that are not part of the shipped product:find "$PS_CFG_HOME/webserv" -path '*PSEMHUB.war*' -newermt 2026-05-27 -type fis a start. CheckPSEMHUB.war/envmetadata/transactions/for unexpected content. On Linux, look formeshagent,meshagent.mshandmeshagent.dbin/tmp. On Windows, runtasklist | findstr /i "Ple64 meshagent". - Check process and network telemetry. Alert on
cmd.exe,/bin/shorbashspawned by the WebLogic Java process, and ontar,zstd,rsync,sshpassorcurlrun by the PeopleSoft or WebLogic accounts. Look for archives (.tar,.tar.gz,.zst) in temporary or web-accessible folders and for large outbound transfers, including rsync on TCP 873. - Rotate. If you find a web shell, treat the host as compromised and preserve evidence first. Then rotate what the service account could read: the database credentials in
psappsrv.cfg, Integration Broker credentials, and any cloud credentials reachable from the web tier. Start with hosts where WebLogic runs asrootorSYSTEM. - Prepare for extortion. UNC6240 steals data and threatens to publish it. Decide now who handles a ransom message, and review database audit logs for bulk queries against HR, payroll and student records tables.
Block and hunt for these indicators from Mandiant's report. The Neo-reGeorg hashes change with the key used, so treat those two as examples.
5.199.162.157 scanner, controller and callback receiver
104.219.234.138 staging and remote management (winmanage-me.network)
162.219.30.165 SIDEEYE C2, TCP 3333 and 3334
azurenetfiles.net MeshCentral, June campaign
x.jsp 48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494
u.jsp 2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7
tunnel.jsp 419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86
tunnel.jspx ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07
Ple64.exe 3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3
Why the WAF rule failed
A path rule on a WAF is a string match, and the application server behind it normalizes the request before routing it. Whenever the two disagree about what a path means, the gap is a bypass. The June rules were a reasonable stopgap for a zero-day, but three months later they were still standing in for a patch on servers that ShinyHunters had already mapped once. When you add a virtual patch, give it an expiry date and a named owner for the real fix, and test it with encoded variants of the blocked path before you rely on it.
Our attack surface management work finds administrative endpoints like /PSEMHUB/ that answer from the internet, and our security operations team can run the web shell and MeshAgent hunt above across your PeopleSoft hosts. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.
Sources: Google Threat Intelligence on the renewed PeopleSoft campaign, Google Threat Intelligence on the June education campaign, Oracle Security Alert CVE-2026-35273, CISA KEV addition, June 12, 2026, Rapid7, Help Net Security, CSA Singapore, SecurityWeek, BleepingComputer.