One URL-encoded character slips attackers past WAFs and onto Oracle PeopleSoft
Google has documented a fresh wave of exploitation of CVE-2026-35273 (CVSS 9.8) by UNC6240, a ShinyHunters-linked actor: the group URL-encodes a single character in the path to bypass WAFs and drop web shells on Oracle PeopleSoft. Patch, disable the EMHub, and hunt for /PSEMHUB/ in every encoded form.
September 26, 2026. Google, through its subsidiary Mandiant, documents a fresh wave of mass exploitation of CVE-2026-35273, an unauthenticated remote-code-execution flaw (CVSS 9.8) in Oracle PeopleSoft. September 26, 2026. The actor UNC6240, linked to ShinyHunters, has modified its exploit to bypass the WAFs that were blocking the vulnerable endpoint. September 2026. Mandiant says it has notified more than 100 organizations whose IP addresses matched vulnerable endpoints, most of them in the United States. Why it matters: the bypass hinges on a single encoded character — and it turns a filter people trusted into a sieve.
The bypass is a single character
The WAF is the last line people assume is airtight. Here it fell without violence. To block the vulnerable endpoint, WAF and reverse-proxy rules matched the literal path /PSEMHUB/. UNC6240 simply URL-encoded one character of the path, writing /%50SEMHUB/ instead of /PSEMHUB/ — %50 being the hexadecimal encoding of the letter P.
The flaw lives in the gap between two layers. Most WAFs and reverse proxies match their rules against the path before URL decoding, so they see %50 and do not recognize the blocked pattern. The PeopleSoft application server, meanwhile, decodes the request and routes it to the vulnerable servlet. Two interpretations of the same byte, and the filter misses. It is the request-smuggling principle applied to path decoding — one normalization divergence, and the rule goes blind.
The gap is systemic, not a one-off. Path normalization — deciding whether a request is /PSEMHUB/ or /%50SEMHUB/ — differs between the proxy layer and the application layer, and every layer that decodes differently is a seam an attacker can aim at. The same class of bug shows up in double-encoding, mixed case, and Unicode normalization. The durable fix is to normalize the path once, at the proxy, before any rule matches — or, failing that, to match rules against both the raw and the decoded form. A WAF that trusts the raw bytes is a WAF one character defeats.
CVE-2026-35273, the flaw behind the filter
CVE-2026-35273 hits the Environment Management Hub, the PSEMHUB (or EMHub) endpoint of PeopleSoft. The flaw is an unsafe Java deserialization: an attacker sends a POST to /%50SEMHUB/hub carrying a serialized Java object, and the servlet deserializes it, leading to unauthenticated remote code execution.
The severity is as much about position as score. PeopleSoft concentrates payroll, human resources, student records and finance for a large share of organizations. Code execution on that application reaches the tables most backup plans treat as the most sensitive. Mandiant notes the actor exploits the flaw to steal data and then threaten to publish it on a leak site — a data-theft extortion pattern UNC6240 has run for years.
From exploit to the SIDEEYE backdoor
The attack chain Mandiant documented is complete and instructive. The actor first identifies targets by sending POST requests to /%50SEMHUB/hub with a serialized Java object. Once deserialization succeeds, it drops two JSP web shells into the PSEMHUB.war directory: x.jsp, which enables cross-platform command execution, and u.jsp, which enables chunked uploads and execution via cmd.exe.
u.jsp is the launch ramp. It uploads Ple64.exe, a signed but trojanized installer that loads SIDEEYE in memory — a C++ backdoor talking to 162.219.30.165 over TCP to steal browser and desktop-application credentials, manage processes and files, and provide an interactive reverse shell and reverse proxy. Alongside it, the actor stages Neo-reGeorg, an open-source tunneling toolkit, and, on Linux hosts, deploys the legitimate RMM tool MeshAgent for persistence.
The detail every operator should sit with: roughly a quarter of the actor’s commands ran as root or NT AUTHORITY\SYSTEM, the rest under PeopleSoft or WebLogic service accounts. On a slice of machines, in other words, the actor already holds the whole system, not just the application.
What to look for on your instances
Google published a precise set of checks. The first is to patch CVE-2026-35273 and disable the Environment Management Hub service in multi-server configurations — or remove the PSEMHUB application entirely in single-server ones. The second is to hunt the access logs of WebLogic for the path and its encoded variants:
grep -iE '%[0-9A-Fa-f]{2}SEMHUB|PSEMHUB' access*.log Then inspect the PSEMHUB.war directory for JSP web shells and other artifacts. Rotate the credentials readable by the PeopleSoft application service account. Hunt for large archive files in temporary or web-accessible directories, and review the database audit logs for bulk queries or exports against HR, payroll and student tables. Finally, monitor outbound traffic from PeopleSoft hosts.
Google also advises preparing for extortion: “Affected organizations should prepare for extortion communications and monitor for potential public exposure of stolen data.”
Extortion as a business model
The current wave is not the first. CVE-2026-35273 was first exploited as a zero-day against academic institutions, for reconnaissance, deploying the MeshCentral agent for persistence, moving laterally over SSH, and running a script that connected to other internal PeopleSoft machines using known username/password pairs. At that stage Mandiant had already notified more than 100 organizations, most of them in the United States.
The new wave’s targets sketch a clear profile: higher education, technology, IT services, healthcare, agriculture, transportation and government. The actor has dropped web shells on dozens of systems. The motive stays the same across sectors — UNC6240 steals data, then threatens to publish it. Google is blunt: the actor runs “a well-established pattern of data theft extortion,” stealing and threatening to release unless the victim pays.
The same group has also claimed the FBIJobs.gov breach, with 2 to 3 TB of data exfiltrated — an operation it frames as a rebuttal of the agency’s accusations rather than extortion. Its spokesperson says the intrusion used an Oracle PeopleSoft zero-day different from CVE-2026-35273. Whatever the truth of those figures, the episode signals sustained focus on this one platform — and an organization that has not yet patched remains squarely in the group’s sights. For an operator, that changes the nature of the response: it is not only about patching an application, but about preparing an extortion-response posture and watching leak sites for your data — preparation here is a control, not paranoia. Organizations holding HR or student records should fold that preparation into the patch cycle, not treat it as a follow-up.
Verdict
If you run Oracle PeopleSoft, apply the CVE-2026-35273 patch and disable or remove PSEMHUB without waiting — the flaw is under active exploitation and extortion follows within days. If you were relying on a WAF for protection, rewrite your rules to normalize the path before matching, or block the encoded variants too: a filter that does not decode is a filter one character defeats. If you hold HR or payroll data in PeopleSoft, treat the access-log and database audit as an immediate priority — an actor running as root on a quarter of the machines leaves more than application-level traces. The lesson reaches beyond PeopleSoft: the boundary between your WAF and your application is a normalization gap, and that is precisely where actors aim. Fixing path normalization at the proxy remains the only durable cure.