The Patch Isn’t the Perimeter: ShinyHunters Just Beat the WAF Rule You Were Counting On
Executive threat briefing, Monday, September 28, 2026
One character. That’s all it took to reopen PeopleSoft.
In June, ShinyHunters broke into more than 100 organizations through an Oracle PeopleSoft zero-day. Defenders wrote WAF rules to stop it. Now the group is back, encoding the letter “P” as %50 and walking straight past those rules, into higher education, healthcare, government and more.
Executive summary
The fix you deployed in June may not be a fix anymore.
On September 25, Google’s Mandiant and Threat Intelligence Group (GTIG) reported that UNC6240, the extortion crew known as ShinyHunters, has resumed mass exploitation of Oracle PeopleSoft through CVE-2026-35273, a 9.8-rated unauthenticated remote code execution flaw.
The twist: the attackers aren’t beating the patch. They’re beating the organizations that never applied it and relied on web application firewall rules instead. By requesting /%50SEMHUB/ rather than /PSEMHUB/, their traffic slips past string-matching rules, while PeopleSoft’s application server decodes the path and serves the vulnerable endpoint anyway.
Mandiant has found web shells on dozens of systems worldwide, a new backdoor called SIDEEYE, and a target list that now spans higher education, technology, IT services, healthcare, agriculture, transportation and government.
If PeopleSoft runs your payroll, HR or student records and you mitigated instead of patched, treat this as an active incident until you prove otherwise.
Why this matters to CISOs and security leaders
PeopleSoft isn’t a peripheral app. It holds payroll, Social Security numbers, bank details, HR files, financial ledgers and student records. For a data-extortion crew, it’s the most valuable single system in the building.
This campaign also exposes a quiet failure in how many enterprises run vulnerability management. When a critical patch is hard to schedule, teams reach for a compensating control, mark the risk as mitigated, and move on. ShinyHunters read the same public guidance defenders did, and built its comeback around the gap.
Mandiant says as much: the group adapted to published defensive guidance and went after organizations that deployed WAF rules but didn’t patch.
Executive insight
Ask your team one question today: “Which of our ‘mitigated’ criticals are mitigated by a rule rather than removed by a patch?” That list is your real exposure. Every entry on it is a bet that attackers won’t find a way around the rule. On PeopleSoft, that bet just lost.
How we got here: from zero-day to relapse
| Date | What happened |
|---|---|
| May 27 – June 9, 2026 | ShinyHunters exploits CVE-2026-35273 as a zero-day, mostly against universities. No patch exists. |
| June 10 | Oracle issues an out-of-band Security Alert and fix. |
| June 11–12 | Mandiant publishes its first report. CISA adds the flaw to the Known Exploited Vulnerabilities catalog. Guidance: patch, or block /PSEMHUB/* at the perimeter if you can’t yet. |
| June – August | The group claims more than 300 compromised PeopleSoft instances across over 100 organizations. Intrusions continue into July using MeshAgent remote access. |
| September 2026 | Renewed mass exploitation using the %50SEMHUB WAF bypass. Targeting expands across sectors and regions. |
| September 25 | Mandiant and GTIG publish the follow-up report with new tooling, IOCs and remediation guidance. |
How the WAF bypass actually works
The vulnerable component is the Environment Management Hub (PSEMHUB), an administrative servlet that should never have been reachable from the internet in the first place.
Many WAF and reverse-proxy rules check the raw request path for the literal string /PSEMHUB. But %50 is simply the URL-encoded form of the letter P. The WAF sees /%50SEMHUB/, finds no match, and waves it through. WebLogic then decodes the path back to /PSEMHUB/ and hands the request to the vulnerable servlet.
The WAF and the application disagreed about what the URL said. The attacker lived in that disagreement.
What nobody is talking about: this is a normalization bug, not a PeopleSoft bug. Any rule that matches a path before decoding is vulnerable to the same trick, on any application. Mandiant’s advice applies broadly: assume attackers will try every percent-encoded, mixed-case or non-normalized variant, and enforce blocking on the normalized path.
Inside the attack chain
1. Quiet verification
Before exploiting anything, the attackers send five to 15 POST requests containing a serialized Java object to /%50SEMHUB/hub. An unpatched server answers with its operating system, without writing files or disrupting service. It’s a silent “you’re vulnerable” check.
The hidden enterprise risk: if you see these probes in your logs with nothing after them, you haven’t dodged the attack. You’ve been shortlisted.
2. Two ways in
Mandiant observed two exploitation methods, both abusing Java deserialization in the hub servlet:
- Web shell deployment. A burst of requests drops JSP files such as
x.jspinto the PSEMHUB directory. The burst likely ensures every node behind a load balancer gets a copy, so checking only one WebLogic node isn’t enough. - Fileless execution. Commands run directly and return output in the HTTP response, with nothing written to disk. On the host, it looks like the WebLogic Java process spawning
cmd.exeor/bin/sh. Detections built on file creation will miss it entirely.
3. Built to dodge detection
The two web shells are single-line JSP files designed to stay quiet. x.jsp takes hex-encoded commands over POST instead of readable query strings, and even assembles the /bin/sh path from character codes to avoid static signatures. u.jsp uploads large files in 150 KB Base64 chunks to get around request-size limits.
4. A new backdoor: SIDEEYE
On Windows servers, the group uploaded a 5.2 MB file called Ple64.exe, disguised as a signed installer for the Light Alloy media player. It’s a trojanized installer carrying a three-stage chain that ends by loading a C++ backdoor, SIDEEYE, entirely in memory. The middle stage is protected with VMProtect.
The sample was signed with a valid Extended Validation code-signing certificate, which GTIG has asked the issuer to revoke. SIDEEYE can steal browser and desktop credentials, manage files and processes, and open reverse shells and proxies.
5. Tunnels and remote control
The attackers also deployed Neo-reGeorg, an open-source toolkit that tunnels SOCKS5 traffic through ordinary web requests, turning the PeopleSoft server into a doorway into the internal network. On Linux hosts they installed MeshAgent, a legitimate remote-management tool, and pointed it at infrastructure dressed up to look like IT or Microsoft services.
Why CISOs are worried
According to Mandiant, a quarter of the attackers’ commands ran as root or SYSTEM, meaning full control of the operating system. The rest ran under PeopleSoft or WebLogic service accounts, which still unlock configuration files, database connection strings and application data. Either way, the attacker can reach the crown jewels.
Who is being targeted
June’s wave hit universities hardest. September’s doesn’t discriminate. Mandiant has confirmed compromises across:
| Sector | Data at risk in PeopleSoft |
|---|---|
| Higher education | Student records, financial aid, staff payroll |
| Healthcare | Employee HR and payroll, benefits data |
| Government | Public employee records, financials |
| Technology and IT services | HR data, and potential downstream access to clients |
| Agriculture and transportation | Payroll, finance, supplier and vendor data |
Competitive pressure: IT services firms deserve special attention. A compromised provider’s PeopleSoft tier can hold credentials and data that reach beyond its own walls, which turns one intrusion into a supply-chain problem for every client.
No encryption. No mercy. Just extortion.
ShinyHunters doesn’t need ransomware. The group steals data, threatens to post it on a leak site and demands payment. Mandiant warns affected organizations to prepare for extortion contact and to watch for public exposure of stolen records.
That changes the incident calculus. Backups don’t help when nothing is encrypted. Business-interruption cover matters less. Breach notification, regulatory exposure under state privacy laws and education and health data rules, and litigation risk matter far more. If you carry cyber insurance, notify your carrier early. Most policies have strict reporting windows.
Winners and losers
| In good shape | Exposed right now |
|---|---|
| Teams that applied Oracle’s June fix | Teams that deployed a WAF rule and deferred the patch |
| Deployments with EMHub disabled or removed | PSEMHUB reachable from the internet |
| WAFs that block on the decoded, normalized path | Rules that match raw strings before decoding |
| EDR watching what the WebLogic process spawns | Detection that only looks for dropped files |
| Organizations on supported PeopleTools versions | Unsupported releases with no fix available |
What security leaders should do next
In the next 24 hours
- Patch. Apply Oracle’s Security Alert fix for CVE-2026-35273 on every PeopleSoft environment, including test and dev. Mandiant is explicit: WAF rules and path blocking are not a substitute.
- Shrink the target. Disable the EMHub service in multi-server setups, or remove the PSEMHUB application in single-server setups, per Oracle’s guidance. Block EMHub and the Integration Broker listening connector from the internet. Mandiant notes this doesn’t break normal user sessions.
- Fix the rule. Until patching is done, make sure your WAF normalizes and decodes paths before matching, and blocks every encoded and mixed-case variant of
/PSEMHUB/.
This week: hunt
- Search WebLogic access logs for
/PSEMHUB/and any encoded variant such as/%50SEMHUB/, especially external POST requests to/huband requests for.jspfiles. - Inspect every node for files that don’t belong in
PSEMHUB.war/orPORTAL.war/, includingx.jsp,u.jsp,tunnel.jsp,tunnel.jspxandPle64.exe. - Alert on process behavior: shells spawned by the WebLogic Java process, especially running
base64 -d,curl,/dev/tcp,tasklistorstart /b. Look for unexpected MeshCentral agents. - Look for data theft: large .tar, .tar.gz or .zst archives in temp or web directories; tar, zstd, rsync, sshpass or curl run by PeopleSoft service accounts; bulk queries against HR, payroll and student tables; and large outbound transfers, including rsync on TCP 873.
If you find anything
- Treat the host as compromised. Preserve evidence before cleanup.
- Rotate every credential the PeopleSoft tier can read: database connection strings in
psappsrv.cfg, Integration Broker credentials and any cloud credentials reachable from the web tier. Start with hosts where WebLogic runs as root or SYSTEM. - Brief legal, communications and your insurer now, and prepare for an extortion demand.
Indicators of compromise
From Mandiant and GTIG’s September 25 report. Web shell hashes vary between samples, so hunt on file names and paths as well as hashes.
| Indicator | Type | Role |
|---|---|---|
5.199.162.157 | IPv4 | Attack controller, scanner and callback receiver |
104.219.234.138 | IPv4 | Exfiltration staging and remote management |
162.219.30.165 | IPv4 | SIDEEYE command and control (TCP 3333 and 3334) |
winmanage-me.network | Domain | MeshCentral staging infrastructure |
azurenetfiles.net, microsoft-entra.net, enroll.azuredevice.cloud | Domains | Microsoft-lookalike MeshAgent infrastructure (May and July intrusions) |
/%50SEMHUB/ | URI | Encoded WAF bypass path |
Ple64.exe3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3 | SHA-256 | Trojanized installer delivering SIDEEYE |
The full IOC set, including web shell hashes and MITRE ATT&CK mapping, is in Mandiant’s report.
Forward this to whoever owns PeopleSoft
The hunt steps above take hours, not weeks. The team that runs PeopleSoft and the team that runs your SOC need to see this briefing today, together.
What happens next
More victims will surface. Web shells are on dozens of systems, and ShinyHunters’ model depends on publicizing stolen data to force payment. Expect leak-site postings and breach notifications over the coming weeks.
Other groups will copy the trick. The bypass is now public and trivially simple. Once a technique is this easy, it rarely stays with one actor.
The lesson will outlive PeopleSoft. Any critical flaw “mitigated” by a string-matching rule is exposed to the same idea. Security leaders should expect boards and regulators to start asking not just “did you mitigate?” but “did you patch?”
Final executive takeaway
ShinyHunters didn’t find a new vulnerability. They found the organizations that treated a firewall rule as a finish line.
Patch PeopleSoft. Take EMHub off the internet. Hunt every node. Rotate the credentials. And then go find every other “mitigated” critical in your environment, because the next %50 is already out there.
Frequently asked questions
What is CVE-2026-35273?
CVE-2026-35273 is a critical (CVSS 9.8) unauthenticated remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools, in the Updates Environment Management component behind the Environment Management Hub (PSEMHUB). It requires no login and no user interaction.
Who is ShinyHunters?
ShinyHunters, tracked by Mandiant as UNC6240, is a financially motivated cybercrime group known for data theft and extortion. It steals data and threatens to publish it on a leak site unless the victim pays.
How does the ShinyHunters WAF bypass work?
The attackers request /%50SEMHUB/ instead of /PSEMHUB/. %50 is the URL-encoded letter P. WAF rules that match the literal path before decoding miss it, while the WebLogic server decodes the path and routes the request to the vulnerable servlet.
Is a WAF rule enough to protect PeopleSoft?
No. Mandiant states that WAF rules and path-based blocking are not a substitute for patching. Apply Oracle’s Security Alert fix, and disable or remove EMHub where it isn’t needed.
What is SIDEEYE?
SIDEEYE is a C++ backdoor delivered by a trojanized installer named Ple64.exe that poses as a Light Alloy media player installer. It runs in memory and can steal credentials, manage files and processes, and provide reverse shell and proxy access.
Which sectors are being targeted?
Mandiant has observed web shells on systems in higher education, technology, IT services, healthcare, agriculture, transportation and government, across multiple countries.
How do I know if my PeopleSoft servers were compromised?
Search WebLogic logs for /PSEMHUB/ and encoded variants, check every node for unexpected .jsp, .jspx and .exe files in PSEMHUB.war and PORTAL.war, look for shell processes spawned by the WebLogic Java process, and review outbound traffic for the published indicators and large data transfers.
Sources
Mandiant and Google Threat Intelligence Group, “ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft” (Sept. 25, 2026); Oracle Security Alert for CVE-2026-35273; CISA Known Exploited Vulnerabilities catalog; BleepingComputer; The Hacker News; Rapid7; Arctic Wolf. Details current as of September 28, 2026. Victim counts claimed by ShinyHunters have not been independently verified.

