Renewed exploitation of CVE-2026-35273 shows how a simple encoded-path change can bypass literal WAF rules and expose vulnerable PeopleSoft systems to unauthenticated remote code execution.
Attackers used Java deserialization for JSP web shell deployment and fileless command execution, followed by credential theft, tunneling, and persistent access.
Teams should verify Oracle remediation independently of WAF controls, preserve server evidence, assess credential exposure, and investigate beyond filesystem artifacts before confirming recovery.
Hexnode XDR can support downstream endpoint investigation with threat hunting and Visual Process Tree, plus isolation, process termination, and file quarantine actions.
Attackers have renewed PeopleSoft exploitation by encoding one character in a request path. On September 25, Google Threat Intelligence Group and Mandiant attributed the campaign to UNC6240, tracked as ShinyHunters.
For security teams investigating PeopleSoft web shell activity, the immediate question extends beyond whether a firewall blocked known requests. Teams must establish whether vulnerable systems remained reachable and whether attackers gained access before remediation.
How the PeopleSoft web shell attack bypasses WAF rules
Oracle identifies CVE-2026-35273 as an unauthenticated remote code execution vulnerability affecting supported PeopleTools versions 8.61 and 8.62. Google reports a CVSS score of 9.8. Oracle published its security alert on June 10, 2026.
The attackers request /%50SEMHUB/ instead of /PSEMHUB/, encoding the letter P. Literal-path WAF rules can miss that representation, while the application server decodes it and reaches the same vulnerable endpoint.
PSEMHUB runs within Oracle WebLogic Server. Google observed Java deserialization abuse in its hub servlet through two methods: JSP web shell deployment and fileless command execution. In the latter, WebLogic’s Java process launches a command shell without creating a web shell file.
Post-exploitation tools included SIDEEYE, Neo-reGeorg, and MeshAgent, supporting credential theft, tunneling, and persistent access. These findings make filesystem checks alone insufficient for assessing exposure.
Treat the bypass as a failure in request filtering, rather than evidence that attackers defeated Oracle’s patch. Validate patch installation independently from WAF configuration, and test how each defensive layer handles equivalent URL representations.
Featured Resource
Cybersecurity kit
Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.
Why application compromise demands a wider investigation
An application incident can involve more than the affected server. Google’s earlier investigation documented internal reconnaissance, credential spraying, and stolen-data publication associated with the campaign. Attackers inspected PeopleSoft and WebLogic configuration files to understand the surrounding infrastructure.
For incident responders, that history supports a broader assessment: identify which accounts, systems, and data the compromised application could reach. Review service-account privileges and administrative connections alongside the initial intrusion evidence.
Coordinate application owners, security analysts, and identity administrators around one incident timeline. Record the exposure window, suspicious activity, containment decisions, and recovery milestones. This helps teams distinguish confirmed compromise from unresolved investigation gaps.
Investigating PeopleSoft web shell exposure
Start with these response priorities:
Confirm remediation coverage. Inventory affected PeopleTools installations and apply Oracle’s guidance. Oracle warns that unsupported releases may also contain the vulnerability; their absence from the supported-version table does not establish safety.
Preserve and review evidence. Examine WebLogic access logs and unexpected files in application directories. Google’s guidance also calls for checking unauthorized staging content and suspicious XML changes.
Assess credential exposure. Identify secrets accessible from compromised systems. Coordinate credential replacement with containment so attackers cannot immediately capture replacement credentials.
Validate recovery. Assign owners to unresolved findings and document the evidence supporting service restoration. Keep monitoring after patch deployment instead of closing the incident solely because installation succeeded.
How Hexnode XDR supports endpoint response
Hexnode XDR can support investigation when suspicious activity reaches enrolled, supported endpoints. Its threat-hunting query engine lets analysts search seven days of historical process and endpoint event data. The Visual Process Tree helps analysts examine process relationships.
Analysts can initiate Isolate Device, Kill Process, Kill Process Tree, and Quarantine File actions. Isolation preserves connectivity to Hexnode XDR, while quarantine encrypts and restricts access to malicious files. These analyst-triggered controls support endpoint containment.
Hexnode XDR supports detection and containment of post-exploitation activity on enrolled, supported endpoints, complementing server-side WebLogic patching and application-tier remediation without replacing either.
Close the vulnerability and verify recovery
A PeopleSoft web shell investigation requires clear ownership across patching, forensics, and endpoint response. Establish what attackers could access, preserve the evidence needed to assess impact, and validate each recovery action.
Make closure an evidence-based decision. Confirm remediation, resolve suspicious activity, and document remaining uncertainty before treating the environment as recovered.
Strengthen PeopleSoft Threat Response
Detect suspicious endpoint activity, contain active threats, and accelerate incident response with Hexnode UEM and XDR.
Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.