{"id":2047,"date":"2026-09-28T14:35:24","date_gmt":"2026-09-28T09:05:24","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=2047"},"modified":"2026-09-30T23:03:09","modified_gmt":"2026-09-30T17:33:09","slug":"peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/","title":{"rendered":"PeopleSoft WAF Bypass Lets UNC6240 Reopen a Critical RCE Campaign"},"content":{"rendered":"<p>Attackers have renewed PeopleSoft exploitation by encoding one character in a request path. On September 25, Google Threat Intelligence Group and Mandiant attributed the campaign to UNC6240, tracked as ShinyHunters.<\/p>\n<p>For security teams investigating PeopleSoft web shell activity, the immediate question extends beyond whether a firewall blocked known requests. Teams must establish whether vulnerable systems remained reachable and whether attackers gained access before remediation.<\/p>\n<h2>How the PeopleSoft web shell attack bypasses WAF rules<\/h2>\n<p>Oracle identifies <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-35273?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=peoplesoft_web_shell\">CVE-2026-35273<\/a> as an unauthenticated remote code execution vulnerability affecting supported PeopleTools versions 8.61 and 8.62. Google reports a CVSS score of 9.8. Oracle published its security alert on June 10, 2026.<\/p>\n<p>The attackers request <code>\/%50SEMHUB\/<\/code> instead of <code>\/PSEMHUB\/<\/code>, encoding the letter P. Literal-path WAF rules can miss that representation, while the application server decodes it and reaches the same vulnerable endpoint.<\/p>\n<p>PSEMHUB runs within Oracle WebLogic Server. Google observed Java deserialization abuse in its hub servlet through two methods: JSP web shell deployment and fileless command execution. In the latter, WebLogic\u2019s Java process launches a command shell without creating a web shell file.<\/p>\n<p>Post-exploitation tools included SIDEEYE, Neo-reGeorg, and MeshAgent, supporting credential theft, tunneling, and persistent access. These findings make filesystem checks alone insufficient for assessing exposure.<\/p>\n<p>Treat the bypass as a failure in request filtering, rather than evidence that attackers defeated Oracle\u2019s patch. Validate patch installation independently from WAF configuration, and test how each defensive layer handles equivalent URL representations.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit.webp?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity-kit\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity-kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            Download the Resource Kit\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Why application compromise demands a wider investigation<\/h2>\n<p>An application incident can involve more than the affected server. Google\u2019s earlier investigation documented internal reconnaissance, credential spraying, and stolen-data publication associated with the campaign. Attackers inspected PeopleSoft and WebLogic configuration files to understand the surrounding infrastructure.<\/p>\n<p>For incident responders, that history supports a broader assessment: identify which accounts, systems, and data the compromised application could reach. Review service-account privileges and administrative connections alongside the initial intrusion evidence.<\/p>\n<p>Coordinate application owners, security analysts, and identity administrators around one incident timeline. Record the exposure window, suspicious activity, containment decisions, and recovery milestones. This helps teams distinguish confirmed compromise from unresolved investigation gaps.<\/p>\n<h3>Investigating PeopleSoft web shell exposure<\/h3>\n<p>Start with these response priorities:<\/p>\n<ol start=\"1\">\n<li><strong>Confirm remediation coverage.<\/strong> Inventory affected PeopleTools installations and apply Oracle\u2019s guidance. Oracle warns that unsupported releases may also contain the vulnerability; their absence from the supported-version table does not establish safety.<\/li>\n<li><strong>Preserve and review evidence.<\/strong> Examine WebLogic access logs and unexpected files in application directories. Google\u2019s guidance also calls for checking unauthorized staging content and suspicious XML changes.<\/li>\n<li><strong>Assess credential exposure.<\/strong> Identify secrets accessible from compromised systems. Coordinate credential replacement with containment so attackers cannot immediately capture replacement credentials.<\/li>\n<li><strong>Validate recovery.<\/strong> Assign owners to unresolved findings and document the evidence supporting service restoration. Keep monitoring after patch deployment instead of closing the incident solely because installation succeeded.<\/li>\n<\/ol>\n<h2>How Hexnode XDR supports endpoint response<\/h2>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> can support investigation when suspicious activity reaches enrolled, supported endpoints. Its threat-hunting query engine lets analysts search seven days of historical process and endpoint event data. The Visual Process Tree helps analysts examine process relationships.<\/p>\n<p>Analysts can initiate <strong>Isolate Device<\/strong>, <strong>Kill Process<\/strong>, <strong>Kill Process Tree<\/strong>, and <strong>Quarantine File<\/strong> actions. <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-device-isolation\/\">Isolation<\/a> preserves connectivity to Hexnode XDR, while quarantine encrypts and restricts access to malicious files. These analyst-triggered controls support endpoint containment.<\/p>\n<p>Hexnode XDR supports detection and containment of post-exploitation activity on enrolled, supported endpoints, complementing server-side WebLogic patching and application-tier remediation without replacing either.<\/p>\n<h3>Close the vulnerability and verify recovery<\/h3>\n<p>A PeopleSoft web shell investigation requires clear ownership across patching, forensics, and endpoint response. Establish what attackers could access, preserve the evidence needed to assess impact, and validate each recovery action.<\/p>\n<p>Make closure an evidence-based decision. Confirm remediation, resolve suspicious activity, and document remaining uncertainty before treating the environment as recovered.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen PeopleSoft Threat Response<\/h5><p>Detect suspicious endpoint activity, contain active threats, and accelerate incident response with Hexnode UEM and XDR.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Attackers have renewed PeopleSoft exploitation by encoding one character in a request path. On September&#8230;<\/p>\n","protected":false},"author":6,"featured_media":2053,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[12,15],"class_list":["post-2047","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zero-day","category-malware","product_category-extended-detection-and-response","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>PeopleSoft Web Shell Attacks: WAF Bypass and Response<\/title>\n<meta name=\"description\" content=\"PeopleSoft web shell attacks exploit WAF gaps. Learn how CVE-2026-35273 works and how to investigate, contain threats, and secure endpoints.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PeopleSoft Web Shell Attacks: WAF Bypass and Response\" \/>\n<meta property=\"og:description\" content=\"PeopleSoft web shell attacks exploit WAF gaps. Learn how CVE-2026-35273 works and how to investigate, contain threats, and secure endpoints.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-28T09:05:24+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-30T17:33:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/PeopleSoft-WAF-Bypass-Lets-UNC6240-Reopen-a-Critical-RCE-Campaign.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"PeopleSoft WAF Bypass Lets UNC6240 Reopen a Critical RCE Campaign\",\"datePublished\":\"2026-09-28T09:05:24+00:00\",\"dateModified\":\"2026-09-30T17:33:09+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\\\/\"},\"wordCount\":630,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/PeopleSoft-WAF-Bypass-Lets-UNC6240-Reopen-a-Critical-RCE-Campaign.png?format=webp\",\"articleSection\":[\"Zero-Day\",\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\\\/\",\"name\":\"PeopleSoft Web Shell Attacks: WAF Bypass and Response\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/PeopleSoft-WAF-Bypass-Lets-UNC6240-Reopen-a-Critical-RCE-Campaign.png?format=webp\",\"datePublished\":\"2026-09-28T09:05:24+00:00\",\"dateModified\":\"2026-09-30T17:33:09+00:00\",\"description\":\"PeopleSoft web shell attacks exploit WAF gaps. Learn how CVE-2026-35273 works and how to investigate, contain threats, and secure endpoints.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/PeopleSoft-WAF-Bypass-Lets-UNC6240-Reopen-a-Critical-RCE-Campaign.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/PeopleSoft-WAF-Bypass-Lets-UNC6240-Reopen-a-Critical-RCE-Campaign.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"PeopleSoft WAF Bypass Lets UNC6240 Reopen a Critical RCE Campaign\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"PeopleSoft WAF Bypass Lets UNC6240 Reopen a Critical RCE Campaign\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"description\":\"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"PeopleSoft Web Shell Attacks: WAF Bypass and Response","description":"PeopleSoft web shell attacks exploit WAF gaps. Learn how CVE-2026-35273 works and how to investigate, contain threats, and secure endpoints.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/","og_locale":"en_US","og_type":"article","og_title":"PeopleSoft Web Shell Attacks: WAF Bypass and Response","og_description":"PeopleSoft web shell attacks exploit WAF gaps. Learn how CVE-2026-35273 works and how to investigate, contain threats, and secure endpoints.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-28T09:05:24+00:00","article_modified_time":"2026-09-30T17:33:09+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/PeopleSoft-WAF-Bypass-Lets-UNC6240-Reopen-a-Critical-RCE-Campaign.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"PeopleSoft WAF Bypass Lets UNC6240 Reopen a Critical RCE Campaign","datePublished":"2026-09-28T09:05:24+00:00","dateModified":"2026-09-30T17:33:09+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/"},"wordCount":630,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/PeopleSoft-WAF-Bypass-Lets-UNC6240-Reopen-a-Critical-RCE-Campaign.png?format=webp","articleSection":["Zero-Day","Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/","url":"https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/","name":"PeopleSoft Web Shell Attacks: WAF Bypass and Response","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/PeopleSoft-WAF-Bypass-Lets-UNC6240-Reopen-a-Critical-RCE-Campaign.png?format=webp","datePublished":"2026-09-28T09:05:24+00:00","dateModified":"2026-09-30T17:33:09+00:00","description":"PeopleSoft web shell attacks exploit WAF gaps. Learn how CVE-2026-35273 works and how to investigate, contain threats, and secure endpoints.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/PeopleSoft-WAF-Bypass-Lets-UNC6240-Reopen-a-Critical-RCE-Campaign.png?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/PeopleSoft-WAF-Bypass-Lets-UNC6240-Reopen-a-Critical-RCE-Campaign.png?format=webp","width":1340,"height":700,"caption":"PeopleSoft WAF Bypass Lets UNC6240 Reopen a Critical RCE Campaign"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/peoplesoft-waf-bypass-lets-unc6240-reopen-a-critical-rce-campaign\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"PeopleSoft WAF Bypass Lets UNC6240 Reopen a Critical RCE Campaign"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"description":"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2047","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=2047"}],"version-history":[{"count":7,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2047\/revisions"}],"predecessor-version":[{"id":2095,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2047\/revisions\/2095"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/2053"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=2047"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=2047"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}