FR
live
tag

#waf-bypass

One URL-encoded character slips attackers past WAFs and onto Oracle PeopleSoft

Google has documented a fresh wave of exploitation of CVE-2026-35273 (CVSS 9.8) by UNC6240, a ShinyHunters-linked actor: the group URL-encodes a single character in the path to bypass WAFs and drop web shells on Oracle PeopleSoft. Patch, disable the EMHub, and hunt for /PSEMHUB/ in every encoded form.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss