Vulnerability
Published 2026-09-25
Verified 2026-09-27

Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8, CISA KEV): UNC6240/ShinyHunters renewed mass exploit — WAF bypass + SIDEEYE (GTIG 25 Sep)

Oracle Security Alert CVE-2026-35273 (10 June 2026; NVD CVSS 3.1 9.8 CRITICAL AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) is an unauthenticated HTTP takeover of PeopleSoft Enterprise PeopleTools Updates Environment Management (PSEMHUB / Environment Management Hub) on supported versions 8.61 and 8.62. CISA added it to KEV on 12 June 2026 (Known ransomware use). UPDATE 25–26 Sep 2026: Mandiant / Google Threat Intelligence Group report renewed UNC6240 (ShinyHunters) mass exploitation: actors bypass literal WAF path blocks by requesting /%50SEMHUB/ (percent-encoded P) so proxies miss /PSEMHUB/ while WebLogic still routes to the vulnerable servlet; web shells (x.jsp / u.jsp and variants) and fileless command execution observed on dozens of systems globally across higher education, technology, IT services, healthcare, agriculture, transportation, and government. On Windows hosts, trojanized Ple64.exe (masquerading as signed Light Alloy media-player installer; EV cert later revoked) loads in-memory SIDEEYE C++ backdoor (C2 162.219.30.165 TCP/3333–3334); MeshCentral agents also used for persistence. June campaign hit education as a zero-day (27 May–9 June); this wave targets orgs that WAF-mitigated but did not patch or disable EMHub. Cybernews (26 Sep) cites Google notifying 100+ organisations. Distinct from desk shinyhunters-fbi-peoplesoft-20260922 (FBI claim of a “new” PeopleSoft zero-day — unconfirmed relation). Primary: Google Cloud / Mandiant GTIG; vendor: Oracle Security Alert; wire: Cybernews.

Product
Oracle PeopleSoft Enterprise PeopleTools (Updates Environment Management / PSEMHUB)
Versions
Affected supported: PeopleTools 8.61 and 8.62 (Oracle risk matrix). Apply Oracle Security Alert patches/mitigations; disable EMHub (multi-server) or remove PSEMHUB (single-server) per Oracle guidance when patching lags.
CVSS
Exploited in Australia?
unknown
Patch to
Apply Oracle Security Alert CVE-2026-35273 patches for PeopleTools 8.61/8.62; disable/remove PSEMHUB/EMHub per Oracle; do not rely on literal /PSEMHUB/ WAF strings — block normalized/percent-encoded variants; hunt PIA WebLogic logs for /PSEMHUB/ and /%50SEMHUB/; inspect PSEMHUB.war for x.jsp/u.jsp/Ple64.exe and MeshCentral; rotate DB/IB/cloud creds reachable from the web tier; review GTIG IoCs

Primary: Google Cloud / Mandiant GTIG — ShinyHunters renewed PeopleSoft mass exploitation (25 Sep 2026) · Vendor: Oracle Security Alert — CVE-2026-35273 PeopleSoft PeopleTools (10 Jun 2026) · CVE: CVE-2026-35273 · Cybernews — Google warns of renewed ShinyHunters PeopleSoft campaign / SIDEEYE (26 Sep 2026)

vulnerabilities cloud identity