A critical PeopleTools flaw became a repeatable intrusion path

Google reports renewed, broad exploitation of CVE-2026-35273 by UNC6240, a group it associates with ShinyHunters. Oracle rates the PeopleSoft Enterprise PeopleTools flaw 9.8 and says it can be exploited remotely without authentication in affected 8.61 and 8.62 deployments.

According to Google, the campaign expanded across sectors and left web shells on dozens of systems globally. Attackers changed /PSEMHUB/ to the encoded form /%50SEMHUB/, defeating protections that matched the literal path before the server decoded it.

A WAF rule is not the repair

A pattern that blocks one request form can miss an equivalent encoded path. Apply Oracle’s fix or disable the vulnerable component as documented, then investigate the full period in which the system was reachable and unpatched.

PeopleSoft is also a route to connected trust

LayerQuestion for defendersEvidence to retain
ApplicationIs PeopleTools 8.61 or 8.62 present, and was EMHub reachable?Version, patch inventory, configuration, access path, and change history
Web tierDid requests reach PSEMHUB or encoded equivalents?PIA WebLogic access logs, reverse-proxy logs, WAF events, and load-balancer records
HostDid WebLogic write or execute unexpected files?Filesystem timeline, JSP or JSPX files, process ancestry, services, tasks, and outbound connections
CredentialsWhich secrets could the PeopleSoft service identity read?Database strings, Integration Broker credentials, cloud keys, service accounts, and rotation evidence

Normalize the request before you decide it was blocked

  • Search PIA WebLogic and upstream logs for /PSEMHUB/, case changes, percent-encoded characters, and POST requests to /hub.
  • Review the deployed PSEMHUB application for unexpected JSP or JSPX files, including names reported by Google such as x.jsp, u.jsp, tunnel.jsp, and tunnel.jspx.
  • Investigate command interpreters or utilities launched by WebLogic, including cmd.exe, /bin/sh, and bash.
  • Review outbound connections, remote-access tooling, and activity consistent with mesh agents or tunnelling.
  • Correlate the host timeline with database, identity, cloud, and Integration Broker activity; the web server may be only the first affected system.

Recover application and credential trust together

  1. 1

    Contain exposed access. Restrict the service while preserving logs and volatile evidence. Do not let containment erase the only record of exploitation.

  2. 2

    Apply Oracle’s remediation. Install and verify the security update. Where patching cannot be immediate, follow Oracle’s documented EMHub disablement or PSEMHUB removal guidance for the deployment model.

  3. 3

    Determine whether code execution occurred. Use web, host, and network evidence to distinguish scanning, exploit attempts, web-shell deployment, and follow-on activity.

  4. 4

    Rotate reachable secrets. Change credentials and keys readable by the PeopleSoft application identity, prioritising database, broker, cloud, and integration trust.

  5. 5

    Rebuild when integrity is uncertain. If attackers achieved code execution and the system cannot be proven clean, restore from a trusted baseline and validate connected systems before returning it to service.

Test controls after URL decoding

Security controls and origin servers do not always interpret a request in the same order. WAF tests should include percent encoding, mixed case, double encoding, path normalization, and alternate separators, then verify that the normalized request seen by the application is the one the control evaluated.