Skip to content
Cybersecurity & InfrastructureUrgency level L3ElevatedActive
CHRONOS Cybersecurity & Infrastructure category illustration. Illustrative only, not specific to this event.
CHRONOS VisualizationCybersecurity & Infrastructure illustration, not specific to this event

ShinyHunters renews mass exploitation of critical Oracle PeopleSoft flaw

Google Mandiant says the ShinyHunters-linked cluster it tracks as UNC6240 has resumed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft, bypassing string-based web-application-firewall mitigations and compromising dozens of systems across multiple sectors and countries.

CHRONOS Wire · September 27 · Alert 4

Audio preparing…
Published
Updated
Revision
r497364
Urgency level
3/5
Elevated
Significance
82
Confidence
91
Market impact
48
Global impact
67

Cliff Notes

  • A known critical PeopleSoft vulnerability is being exploited again at scale. The attackers found a simple way around some WAF-only defenses. Organizations that applied Oracle's patch are materially better protected; WAF rules alone are not sufficient.

Google Mandiant reported renewed mass exploitation of Oracle PeopleSoft CVE-2026-35273, a critical unauthenticated remote-code-execution flaw. Attackers bypassed string-based WAF rules by URL-encoding a character in the vulnerable PSEMHUB path, then deployed web shells and executed commands. Reuters reported the renewed campaign after Mandiant's disclosure. This is a late-discovered recovery event: the underlying disclosure predates the current 75-minute window and is not represented as newly occurring during it.

ELI5: Plain-English Explanation

Some organizations put a guard at the front door instead of fixing the broken lock. Attackers changed how they wrote the address, got past the guard, and reached the same broken lock. The real fix is installing Oracle's security update and checking for signs attackers already got in.

Why Urgent Level 3

PeopleSoft commonly handles HR and other sensitive enterprise data, exploitation is active, affected systems span government, healthcare, transportation, technology, agriculture and higher education, and the bypass undermines a mitigation some defenders relied on.

What Changed

Mandiant observed renewed exploitation after earlier defensive guidance, with attackers bypassing literal-path WAF rules using URL encoding and compromising dozens of systems.

What Is Genuinely New

The material novelty is not another article about the summer campaign; it is Mandiant's confirmation that mass exploitation resumed and that attackers adapted specifically to bypass WAF mitigations used by organizations that had not installed Oracle's patch.

CHRONOS Bottom Line

Treat exposed, unpatched PeopleSoft environments as actively targeted. Patch status and compromise hunting matter more than reliance on path-matching WAF rules.

Direct Effects

  • Risk of unauthenticated remote code execution on vulnerable PeopleSoft systems
  • Web-shell deployment and persistent unauthorized access
  • Potential exposure of HR, personnel and other enterprise data
  • Incident-response and service-disruption costs for affected organizations

Indirect / Second-Order Effects

  • Higher third-party and supply-chain cyber risk where PeopleSoft integrates with identity, payroll or enterprise systems
  • Increased regulatory and disclosure risk for compromised organizations
  • Pressure on organizations to accelerate Oracle patching and credential rotation

Market Reality Gap

The campaign is operationally significant but there is not yet evidence of broad market-wide disruption or a systemic outage. Cybersecurity vendors may see higher defensive demand, but direct financial impact remains organization-specific.

Negative Evidence / Invalidation

  • The vulnerability is known and Oracle has issued an update
  • Mandiant's reporting indicates organizations that patched are not relying solely on the bypassed WAF mitigation
  • Public evidence reviewed does not establish compromise of every exposed PeopleSoft deployment
  • No evidence reviewed shows systemic disruption of national critical infrastructure from this campaign

Resilience / Shock Absorbers

  • Oracle patching removes the known vulnerable condition
  • Disabling or removing the exposed Environment Management Hub/PSEMHUB component can reduce attack surface where operationally feasible
  • Log review, web-shell hunting and credential rotation can contain post-exploitation risk

Shock Absorbers

  • Existing vendor patch availability
  • Network segmentation and least-privilege service accounts
  • Endpoint and application monitoring capable of detecting web-shell or command-execution behavior

Confirmation Signals

  • Additional Mandiant or Oracle advisories confirming expanded exploitation
  • CISA or other national cyber authorities adding emergency guidance or exploited-vulnerability directives
  • More independently confirmed compromises across government or critical-infrastructure operators

Invalidation Signals

  • Evidence that reported renewed activity was limited or misattributed
  • Rapid patch adoption accompanied by a sustained collapse in exploitation telemetry
  • Mandiant materially revising its assessment

What Would Prove CHRONOS Wrong

Credible vendor or government evidence showing the renewed campaign was not mass exploitation, was not linked to the described PeopleSoft vulnerability, or did not bypass the reported WAF mitigations would materially invalidate this assessment.

What Would Raise This to Level 4

  • Confirmed compromise of major national critical-infrastructure operators
  • Large-scale theft of sensitive government or healthcare records
  • Evidence of destructive activity, ransomware, or widespread service outages
  • A distinct unpatched zero-day becoming part of the same campaign

What Would Lower This Alert

  • Broad patch adoption and declining exploitation telemetry
  • No additional material compromises over the next several days
  • Confirmed containment of affected systems without secondary propagation

Watch Windows

Next 24 hours: additional victim disclosures and government advisories
Next 72 hours: evidence of campaign expansion, data theft or secondary extortion
Next 7 days: patch adoption, new indicators of compromise and attribution confidence

Uncertainties / Known Unknowns

  • Total number of compromised organizations is not yet public
  • Full volume and sensitivity of stolen data are unknown
  • Relationship between this campaign and separate claims involving FBI systems remains incompletely verified

Detailed Analysis

Active exploitation has moved beyond the original wave because attackers adapted to defender behavior. The key risk distinction is patched versus merely WAF-mitigated PeopleSoft deployments.

Evidence chain

Google Mandiant is the primary technical source for renewed exploitation and the WAF-bypass behavior. Reuters independently reported Mandiant's findings. Secondary technical reporting describes exploitation of CVE-2026-35273 and web-shell deployment.

Operational significance

The campaign affects multiple sectors and countries and demonstrates that literal-path WAF rules can be bypassed. Organizations that delayed Oracle's patch because they deployed a WAF workaround face elevated exposure.

Limits of current evidence

The public record does not yet support claims of economy-wide disruption, compromise of all exposed systems, or destructive effects. Those limits cap urgency at Elevated.

Affected Countries

  • United States
  • Multiple countries

Affected Industries

  • Government
  • Higher Education
  • Healthcare
  • Technology
  • IT Services
  • Agriculture
  • Transportation

Affected Companies

  • Oracle
  • Google

Affected Assets

  • Oracle PeopleSoft
  • CVE-2026-35273
  • Enterprise HR and administrative systems

Sources / Evidence

  1. 01
    Source 1
    2026-09-25
  2. 02
    Source 2
    2026-09-26