ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
ShinyHunters is mass-exploiting Oracle PeopleSoft CVE-2026-35273, bypassing WAF rules to plant web shells.
Mandiant and Google Threat Intelligence Group say UNC6240, also known as ShinyHunters, resumed mass exploitation of Oracle PeopleSoft flaw CVE-2026-35273. The group requests /%50SEMHUB/ so WAF rules matching /PSEMHUB/ before URL decoding miss the Environment Management Hub servlet, then abuses Java deserialization to deploy JSP web shells or run fileless commands. Dozens of systems were hit across higher education, technology, IT services, healthcare, agriculture, transportation, and government. Oracle issued an out-of-band patch on June 10, 2026; Mandiant says WAF rules are not a substitute for patching.