ShinyHunters Bypasses Oracle PeopleSoft Mitigation, Expands Zero-Day Attacks Globally
ShinyHunters has bypassed WAF mitigations for a critical Oracle PeopleSoft zero-day and resumed attacks globally, Mandiant and Google's Threat Intelligence Group say. The original patch remains effective, but organizations should check for compromise and rotate credentials.
The vulnerability is a Java deserialization flaw in Oracle's PeopleSoft Environment Management Hub servlet. It allows attackers to deploy web shells or execute fileless commands on vulnerable servers. Oracle PeopleSoft is enterprise business software used by large organizations, universities, governments and corporations to manage human resources, finance, supply chain and student administration. The remote code execution bug was caused by unsafe deserialization of Java objects in the PSEMHUB servlet. ShinyHunters exploited it for days in June 2026, initially targeting higher education institutions, stealing sensitive files and enabling extortion campaigns.
Oracle fixed the issue on June 10, 2026, in versions 8.61 and 8.62. The bug was assigned CVE-2026-35273 and given a severity score of 9.8 out of 10, or critical. The U.S. Cybersecurity and Infrastructure Security Agency added it to its Known Exploited Vulnerabilities catalog on June 12, giving federal agencies a three-day deadline to patch.
Oracle also provided mitigation measures for organizations that could not install the patch at the time. Mandiant and GTIG now say ShinyHunters found a way to bypass those mitigations and is again exploiting the flaw against organizations running unpatched versions of the software.
The two organizations said the new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall rules that block the vulnerable PSEMHUB endpoint. They said the campaign has expanded globally. According to the researchers, the threat actor bypassed string-based WAF rules by URL-encoding a single character in the request path, requesting /%50SEMHUB/ instead of /PSEMHUB/. Many WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet. That allows the actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure.
Initially, ShinyHunters focused mostly on higher education institutions. In this wave, the group is casting a wider net and deploying web shells on dozens of systems globally, including in technology, IT services, healthcare, agriculture, transportation and government. ShinyHunters are known for extortion. They are using the PeopleSoft vulnerability to gain persistent access and steal credentials, allowing them to move laterally through target environments and exfiltrate sensitive data such as HR or payroll records.
The patch still works. If an organization applied Oracle's fix for CVE-2026-35273, the WAF bypass should not matter, because it works around the mitigation, not the underlying vulnerability fix. Google and Mandiant advise organizations to apply the Oracle Security Alert issued when the zero-day was first disclosed. They also recommend disabling the Environment Management Hub service in multi-server configurations or removing the PSEMHUB application entirely in single-server configurations. Organizations should search PIA WebLogic access logs for requests to /PSEMHUB and any percent-encoded variant, inspect <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/ for files that are not part of the shipped product, rotate all credentials the PeopleSoft application service account can read, and monitor outbound traffic from PeopleSoft hosts for the network indicators listed in the report.