ShinyHunters Exploit Critical PeopleSoft Vulnerability with Bypass Technique
Google's Mandiant and Threat Intelligence Group have detected a mass-exploitation campaign by ShinyHunters, targeting vulnerable Oracle PeopleSoft servers. The cybercrime group is exploiting CVE-2026-35273, a critical vulnerability previously used as a zero-day between May 27 and June 9.
Oracle issued an emergency security update for the flaw on June 10. However, ShinyHunters has modified its attacks to bypass organizations that attempted to mitigate the vulnerability using web application firewall (WAF) rules instead of installing the patch.
The attackers are replacing the letter 'P' with its URL-encoded equivalent and requesting /%50SEMHUB/ instead of /PSEMHUB/, which some WAFs fail to recognize. This technique is being used against organizations in various industries, including higher education, technology, healthcare, and government.
Mandiant recommends that PeopleSoft administrators install Oracle's CVE-2026-35273 security update and disable or remove the Environment Management Hub where possible. They should also search logs for both normal and encoded /PSEMHUB/ requests and inspect PeopleSoft directories for unexpected JSP or executable files.