Home › Intelligence › Brief
VULNERABILITY BRIEF 🟠 High ThreatIntel

ShinyHunters Bypasses WAFs to Exploit Oracle PeopleSoft RCE (CVE‑2026‑35273)

The ShinyHunters extortion gang is leveraging a percent‑encoding trick to evade WAF rules and reach the unauthenticated remote code execution flaw in Oracle PeopleSoft (CVE‑2026‑35273). The technique underscores the need for continuous validation of security controls and auditable patch management.

Verisq™ Intelligence · 📅 September 27, 2026 · 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
bleepingcomputer.com

ShinyHunters Bypasses WAFs to Exploit Oracle PeopleSoft RCE (CVE‑2026‑35273)

What It Is – The UNC‑6240 “ShinyHunters” extortion gang is using a percent‑encoding trick (e.g., /%50SEMHUB/) to evade web‑application‑firewall (WAF) signatures that block the vulnerable PeopleSoft /PSEMHUB/ endpoint. The technique lets the attackers reach the unpatched Oracle PeopleSoft flaw and achieve unauthenticated remote code execution.

Exploitability – The CVE was publicly disclosed and patched in June 2026, but many organizations remain unpatched. The WAF‑bypass method works against devices that compare the raw URL before decoding, so active exploitation is observed in the wild. No public proof‑of‑concept is required beyond the encoded request.

Affected Products – Oracle PeopleSoft (any version vulnerable to CVE‑2026‑35273) and any front‑end WAF or reverse‑proxy that does not normalize URL‑encoding before rule evaluation.

Why It Matters for Trust & Control Assurance

  • Demonstrates that a single control (WAF rule) can give a false sense of security if not continuously validated against evolving attacker techniques.
  • Highlights the need for evidence‑driven patch management and configuration‑as‑code practices that can be audited across frameworks (NIST CSF, ISO 27001, etc.).
  • Shows that robust log‑based detection of encoded request patterns is a critical control objective for defending against web‑layer exploits.

Recommended Actions

  1. Deploy Oracle’s security update for CVE‑2026‑35273 on all PeopleSoft instances without delay.
  2. Review and harden WAF/Reverse‑proxy rules to decode URLs before pattern matching; test with common encodings (%50, mixed‑case, etc.).
  3. Search WebLogic and proxy access logs for /PSEMHUB/ and encoded variants (/%50SEMHUB/, %50seMHUB, etc.) to identify any prior exploitation attempts.
  4. Integrate WAF rule validation and patch‑status checks into a continuous control‑monitoring program to produce defensible audit evidence.

Source: BleepingComputer – ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

📰 Original Source
https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/ ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →