
ShinyHunters expands Oracle PeopleSoft exploitation after bypassing WAF defenses
Google Threat Intelligence Group and Mandiant report renewed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft, with attackers adapting their exploit to bypass WAF mitigations and deploying web shells on dozens of systems globally across government, healthcare, transportation, technology, agriculture, IT services and higher education.
CHRONOS Wire · September 26 · Alert 2
- Published
- Updated
- Revision
- r497331
Cliff Notes
- A known critical PeopleSoft flaw is being mass-exploited again. Attackers adapted to bypass WAF workarounds; dozens of systems across multiple critical sectors have web shells. Fully patched systems are the key shock absorber.
The material change is not the original PeopleSoft vulnerability, which Oracle patched in June, but a renewed campaign that defeats a commonly used mitigation. Google says UNC6240/ShinyHunters modified requests to bypass string-based WAF rules, reached systems whose operators may have believed they were protected, and progressed to web-shell deployment and hands-on-keyboard activity. Google recommends applying Oracle's patch rather than relying on WAF blocking.
ELI5: Plain-English Explanation
Some organizations put a security guard in front of a known broken door instead of fixing the door. The attackers changed how they approached the door so the guard did not recognize them. Organizations that actually installed the repair are better protected.
Why Urgent Level 3
PeopleSoft supports HR and other critical enterprise functions, and the campaign has expanded beyond universities into government, healthcare and transportation. Organizations relying only on WAF rules may remain exposed despite believing they mitigated the flaw.
What Changed
ShinyHunters adapted its exploit to bypass published WAF defenses and expanded targeting across multiple sectors worldwide.
What Is Genuinely New
Google/Mandiant disclosed renewed mass exploitation, WAF-bypass adaptation and web-shell deployment on dozens of systems globally; this is materially different from repeated reporting about the original May-June zero-day campaign.
CHRONOS Bottom Line
This is an active enterprise exploitation campaign against organizations that did not fully patch PeopleSoft. The risk is elevated but not evidence of universal PeopleSoft compromise.
Direct Effects
- Potential remote compromise of unpatched PeopleSoft servers
- Credential exposure and persistent remote access after web-shell deployment
- Operational and data-security risk for affected organizations
Indirect / Second-Order Effects
- Incident-response and patching costs across PeopleSoft users
- Potential downstream exposure of HR, identity and enterprise credentials
- Heightened cyber-risk scrutiny for Oracle enterprise software environments
Market Reality Gap
No evidence yet establishes broad financial-system disruption or a material Oracle-wide service outage; operational cyber risk currently exceeds demonstrated market impact.
Negative Evidence / Invalidation
- Oracle released a patch for CVE-2026-35273 in June
- The renewed campaign particularly targets organizations that used WAF mitigations without applying the patch
- Google reports dozens of compromised systems, not universal compromise
- Reuters says it could not corroborate ShinyHunters' separate claim regarding FBI data access through PeopleSoft
Resilience / Shock Absorbers
- Apply Oracle's security patch
- Disable or remove the vulnerable Environment Management Hub where appropriate
- Hunt for encoded PSEMHUB requests and unauthorized JSP web shells
- Rotate credentials accessible to the PeopleSoft application service account
Confirmation Signals
- Additional vendor or government confirmation of affected organizations
- CISA or Oracle emergency guidance escalation
- Material increase in confirmed compromised systems or sectors
- Verified data theft or operational disruption at major institutions
Invalidation Signals
- Evidence that observed compromises are limited to previously known victims
- Rapid remediation with no additional exploitation
- Forensic findings materially narrowing the campaign's reach
What Would Prove CHRONOS Wrong
Evidence that the reported renewed exploitation was misattributed, materially overstated, or did not bypass the stated mitigations would invalidate the elevated assessment.
What Would Raise This to Level 4
- Confirmed compromise of major critical-infrastructure operators
- Large-scale sensitive-data theft
- Exploitation spreading substantially beyond currently reported dozens of systems
- Evidence patched systems are also exploitable
What Would Lower This Alert
- Widespread patch adoption
- No meaningful expansion in confirmed victims
- Successful containment and credential rotation
- Vendor or government evidence that exploitation has materially subsided
Watch Windows
- Next 24 hours for victim disclosures and government advisories
- Next 72 hours for scope clarification and additional indicators
- Next 7 days for remediation effectiveness and downstream breaches
Uncertainties / Known Unknowns
- Exact number and identities of compromised organizations remain undisclosed
- Full extent of data theft and lateral movement is not yet known
- ShinyHunters' separate FBI breach claim remains uncorroborated by Reuters
Detailed Analysis
The campaign demonstrates adaptation to defensive guidance and highlights the danger of compensating controls being treated as substitutes for patching.
Attack evolution
Google says UNC6240 URL-encoded a character in the vulnerable PSEMHUB path, bypassing literal string-based WAF rules while PeopleSoft decoded and routed the request normally.
Observed scope
Mandiant observed web shells on dozens of systems globally spanning higher education, technology, IT services, healthcare, agriculture, transportation and government.
Risk boundary
The vulnerability is patchable and the evidence does not show universal compromise. Organizations that applied Oracle's fix have a materially stronger defensive position than those relying on perimeter rules alone.
Affected Countries
- United States
- Global
Affected Industries
- Government
- Healthcare
- Transportation
- Technology
- IT Services
- Higher Education
- Agriculture
Affected Companies
- Oracle
- Alphabet/Google
Affected Assets
- Oracle PeopleSoft
- CVE-2026-35273
Sources / Evidence
- 01
- 02
- 03