ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
ShinyHunters resumed large‑scale attacks exploiting CVE‑2026‑35273 in Oracle PeopleSoft, using URL‑encoded paths to bypass WAFs and deploy web shells across education, healthcare, and government sectors. Google Cloud and Mandiant advise immediate patching, disabling the vulnerable service, and checking logs for encoded requests. The campaign is active and widespread.
The flaw identified as CVE‑2026‑35273 resides in Oracle PeopleSoft’s Environment Management Hub servlet. Exploitation is achieved by sending a URL‑encoded path such as /%50SEMHUB/ that evades string‑based WAF rules but is decoded by the PeopleSoft server, allowing a malicious Java deserialization payload to reach the vulnerable endpoint. Mandiant and Google Threat Intelligence Group have observed the attacker delivering both web‑shell files and file‑less command output through this mechanism. Any organization that runs Oracle PeopleSoft and has not applied the out‑of‑band patch released on June 10 2026 is exposed. The campaign has been seen across higher education, healthcare, agriculture, transportation and government installations, with dozens of systems worldwide receiving malicious POST requests. Logs may show five to 15 verification requests to /%50SEMHUB/hub before further activity occurs. Apply the Oracle Security Alert patch for CVE‑2026‑35273 without delay and, where patching cannot be immediate, disable the Environment Management Hub service or remove the PSEMHUB application. Search access logs for both literal and percent‑encoded variants of the path, and inspect the PSEMHUB.war directory for unexpected JSP files such as x.jsp or tunnel.jsp. Rotate credentials used by the PeopleSoft service account and monitor outbound traffic for indicators of compromise.