Google and Mandiant Report New Mass Attacks on Oracle PeopleSoft via CVE-2026-35273
Google Threat Intelligence Group and Mandiant have observed renewed mass exploitation of a critical vulnerability in Oracle PeopleSoft. Attackers bypassed some WAF rules using a percent-encoded path to the vulnerable endpoint.

CVE-2026-35273 PeopleSoft is once again being actively exploited at scale. Google Threat Intelligence Group and Mandiant said they attribute the new campaign to the UNC6240 cluster, which they associate with the ShinyHunters designation. According to their findings, attackers are using URL encoding to bypass some web application firewall and proxy server rules.
Oracle describes the vulnerability as an unauthenticated, network-exploitable flaw that allows remote code execution. It affects Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 and has a CVSS score of 9.8 out of 10. Oracle has already made a security update and mitigations available.
CVE-2026-35273 PeopleSoft and Bypassing Path Filters
The observed protection bypass involves writing the letter “P” in the endpoint path in percent-encoded form. Instead of the literal path /PSEMHUB/, attackers sent requests to /%50SEMHUB/. The %50 sequence is evaluated as the letter P after URL decoding.
This variant may pass through WAF or proxy rules that compare the URL path before decoding it and block only the exact string /PSEMHUB/. Google warned that organizations relying solely on such a filter without deploying the fix may have remained exposed to active attacks.
This is therefore not merely a theoretically described flaw or an isolated exploit attempt. Google and Mandiant said they observed webshells deployed on dozens of systems across multiple sectors. They also observed fileless command execution, in which the attacker does not necessarily create a separate file on disk.
What Administrators Can Check
PeopleSoft is among the widely used enterprise systems and is also used in the public sector and education. Successful exploitation of this vulnerability may allow an attacker to take over the vulnerable application server. In this case, a WAF should not replace patching but can serve only as an additional layer of protection.
Oracle recommends applying the available fix and applicable mitigations. Administrators should also review PeopleSoft and WebLogic logs for requests targeting percent-encoded PSEMHUB variants. New or unusual JSP files may also be relevant, as they could indicate the deployment of a webshell.
- Verify that PeopleTools 8.61 and 8.62 systems have received the fix for CVE-2026-35273.
- Check whether WAFs and reverse proxies normalize URL paths before evaluating rules.
- Search application and web logs for requests with a percent-encoded path, including /%50SEMHUB/.
- Investigate the presence of new JSP files and signs of unusual command execution.
Campaign Attribution and Unanswered Questions
The attribution of the activity to the UNC6240 cluster and the group referred to as ShinyHunters is an assessment by Google and Mandiant. It is not a publicly independently proven identity of specific perpetrators. Neither a complete list of affected organizations nor the extent of any potential data exfiltration in this new wave has been publicly confirmed.
Further information may come from Oracle or affected organizations’ announcements. It will also be important to monitor whether WAF vendors release updated rules that account for normalization and URL decoding when checking paths.
Sources
- Google Cloud Blog / Google Threat Intelligence Group and Mandiant – Confirms the renewed exploitation campaign, the URL-encoding technique used to bypass some WAF rules, webshells, and recommended remediation steps.
- Oracle Security Alert Advisory – CVE-2026-35273 – Confirms the affected PeopleSoft PeopleTools versions, unauthenticated remote code execution, CVSS 9.8, and the availability of fixes and mitigations.
- BleepingComputer – Independently reports on the renewed exploitation and WAF bypass using URL encoding.
Verified and updated: 27. 09. 2026 06:22



