ShinyHunters has resumed widespread attacks against Oracle PeopleSoft servers, using a simple change to web requests to get past some web application firewall (WAF) rules. Mandiant and Google Threat Intelligence Group say the campaign targets systems that remain vulnerable to CVE-2026-35273, a critical PeopleTools flaw Oracle patched in June. Google Cloud Blog
How the PeopleSoft WAF bypass works
After the vulnerability became public, some organizations blocked requests to the affected /PSEMHUB/ path at their WAF. According to Mandiant, the attackers changed one character in that path to its URL-encoded form. Certain WAF rules checked the request before decoding it, while the PeopleSoft server decoded it and passed the request to the vulnerable component. That allowed attacks through defenses that appeared to block the original path. Google Cloud Blog
Mandiant says the renewed campaign has placed web shells on dozens of systems worldwide, including organizations in higher education, healthcare, government, technology, and transportation. Researchers also observed follow-on tools used for remote access and internal movement, including the SIDEEYE backdoor. Those findings describe systems Mandiant investigated; they do not establish that every targeted organization suffered data theft. Google Cloud Blog
What PeopleSoft administrators should do
Oracle says CVE-2026-35273 affects supported PeopleTools versions 8.61 and 8.62. The flaw can be exploited remotely without authentication and may lead to code execution. Organizations should apply Oracle’s security update promptly instead of relying on a WAF rule as their primary protection. CVE-2026-35273
Mandiant also advises administrators to review WebLogic access logs for requests to /PSEMHUB/ and encoded variations, inspect the PeopleSoft web directories for unexpected files, and investigate unusual remote management tools or outbound connections. If a web shell is found, the affected server should be treated as compromised and credentials accessible from it should be rotated.

