What happened
A critical PeopleTools flaw became a repeatable intrusion path
Google reports renewed, broad exploitation of CVE-2026-35273 by UNC6240, a group it associates with ShinyHunters. Oracle rates the PeopleSoft Enterprise PeopleTools flaw 9.8 and says it can be exploited remotely without authentication in affected 8.61 and 8.62 deployments.
According to Google, the campaign expanded across sectors and left web shells on dozens of systems globally. Attackers changed /PSEMHUB/ to the encoded form /%50SEMHUB/, defeating protections that matched the literal path before the server decoded it.
A WAF rule is not the repair
Exposure
PeopleSoft is also a route to connected trust
| Layer | Question for defenders | Evidence to retain |
|---|---|---|
| Application | Is PeopleTools 8.61 or 8.62 present, and was EMHub reachable? | Version, patch inventory, configuration, access path, and change history |
| Web tier | Did requests reach PSEMHUB or encoded equivalents? | PIA WebLogic access logs, reverse-proxy logs, WAF events, and load-balancer records |
| Host | Did WebLogic write or execute unexpected files? | Filesystem timeline, JSP or JSPX files, process ancestry, services, tasks, and outbound connections |
| Credentials | Which secrets could the PeopleSoft service identity read? | Database strings, Integration Broker credentials, cloud keys, service accounts, and rotation evidence |
Hunt
Normalize the request before you decide it was blocked
- Search PIA WebLogic and upstream logs for
/PSEMHUB/, case changes, percent-encoded characters, and POST requests to/hub. - Review the deployed PSEMHUB application for unexpected JSP or JSPX files, including names reported by Google such as
x.jsp,u.jsp,tunnel.jsp, andtunnel.jspx. - Investigate command interpreters or utilities launched by WebLogic, including
cmd.exe,/bin/sh, andbash. - Review outbound connections, remote-access tooling, and activity consistent with mesh agents or tunnelling.
- Correlate the host timeline with database, identity, cloud, and Integration Broker activity; the web server may be only the first affected system.
Response
Recover application and credential trust together
- 1
Contain exposed access. Restrict the service while preserving logs and volatile evidence. Do not let containment erase the only record of exploitation.
- 2
Apply Oracle’s remediation. Install and verify the security update. Where patching cannot be immediate, follow Oracle’s documented EMHub disablement or PSEMHUB removal guidance for the deployment model.
- 3
Determine whether code execution occurred. Use web, host, and network evidence to distinguish scanning, exploit attempts, web-shell deployment, and follow-on activity.
- 4
Rotate reachable secrets. Change credentials and keys readable by the PeopleSoft application identity, prioritising database, broker, cloud, and integration trust.
- 5
Rebuild when integrity is uncertain. If attackers achieved code execution and the system cannot be proven clean, restore from a trusted baseline and validate connected systems before returning it to service.
Defender note
Test controls after URL decoding
Security controls and origin servers do not always interpret a request in the same order. WAF tests should include percent encoding, mixed case, double encoding, path normalization, and alternate separators, then verify that the normalized request seen by the application is the one the control evaluated.