Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
UNC6240 bypasses WAFs to mass-exploit Oracle PeopleSoft CVE-2026-35273 and deploy web shells and SIDEEYE.
Google-owned Mandiant warns that ShinyHunters-linked UNC6240 is again mass-exploiting CVE-2026-35273, a CVSS 9.8 unauthenticated remote-code-execution flaw in Oracle PeopleSoft. The group bypasses web-application firewalls by URL-encoding a single character in the PSEMHUB path, then uses Java deserialization to plant JSP web shells, a signed Ple64.exe loader for the SIDEEYE backdoor, MeshAgent, and Neo-reGeorg tunnels. The flaw was first used as a zero-day against academic institutions; Mandiant previously notified more than 100 organizations, mostly in the United States, and the new wave hits education, technology, healthcare, government, and other sectors. Separately, ShinyHunters claim they breached FBIJobs.gov with a different PeopleSoft zero-day and took about 2-3 TB of data, saying it was not for ransom.