ShinyHunters Exploit Oracle PeopleSoft Again: What You Need to Know

ShinyHunters hackers bypassed mitigations to exploit a critical Oracle PeopleSoft vulnerability. Applying patches remains essential to defend against expanded global attacks.

ShinyHunters Exploit Oracle PeopleSoft Again: What You Need to Know
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

How Are ShinyHunters Exploiting Oracle PeopleSoft Again?

ShinyHunters, a notorious hacking group, has resumed exploiting a critical remote code execution (RCE) vulnerability in Oracle PeopleSoft's Environment Management Hub (PSEMHUB) servlet. This flaw, tied to unsafe deserialization of Java objects, allows attackers to execute arbitrary code on vulnerable servers, potentially deploying web shells or executing fileless commands without detection.

Originally disclosed and patched in mid-2026 (CVE-2026-35273), this vulnerability had a mitigation bypass introduced by the hackers themselves. They have cleverly modified their exploitation technique to evade Web Application Firewall (WAF) rules by URL-encoding part of the request path (using /%50SEMHUB/ instead of /PSEMHUB/). Because many WAFs check the path before decoding and Oracle’s PeopleSoft server decodes afterwards, the malicious request reaches the vulnerable endpoint undetected.

This exploitation method compromises organizations running unpatched versions of PeopleSoft globally.

Who Is at Risk and What Are the Consequences?

Dark Web Intelligence on X: "🚨 GOOGLE/MANDIANT: SHINYHUNTERS RENEWS MASS  EXPLOITATION OF ORACLE PEOPLESOFT FLAW CVE-2026-35273 Mandiant and Google  Threat Intelligence Group (GTIG) report a new wave of mass exploitation of  Oracle
Dark Web Intelligence on X: "🚨 GOOGLE/MANDIANT: SHINYHUNTERS RENEWS MASS EXPLOITATION OF ORACLE PEOPLESOFT FLAW CVE-2026-35273 Mandiant and Google Threat Intelligence Group (GTIG) report a new wave of mass exploitation of Oracle

Initially targeting higher education institutions, ShinyHunters have broadened their campaign to include sectors such as technology, healthcare, government, agriculture, IT services, and transportation. Affected organizations primarily include large enterprises and institutions utilizing PeopleSoft for managing human resources, finance, supply chains, or student systems.

Attackers use this vulnerability to deploy persistent web shells, steal credentials, and move laterally within networks. This increases the risk of data theft, including sensitive information like payroll, HR records, and other confidential corporate data, which can then be leveraged for extortion or further cyberattacks.

How Can Affected Organizations Effectively Defend Themselves?

The most reliable defense remains applying Oracle’s official patch for CVE-2026-35273. The patch fixes the underlying vulnerability and renders the WAF bypass ineffective. Merely relying on mitigations or WAF rules without patching leaves systems exposed.

Additional recommended actions include:

  • Disabling the Environment Management Hub (EMHub) service in multi-server setups or removing the PSEMHUB application in single-server deployments.
  • Analyzing WebLogic access logs for suspicious requests targeting /PSEMHUB or encoded variants.
  • Inspecting application directories for unauthorized files that may indicate web shell presence.
  • Rotating credentials accessible by the PeopleSoft application service account to reduce risk of credential theft abuse.
  • Monitoring outbound network traffic from PeopleSoft hosts for known malicious indicators.

These steps help identify potential compromise and prevent attackers from persisting or spreading inside networks.

Key Takeaway: Patch Promptly to Eliminate Risk

The Defensive Line Weekly #40: 20–27 September 2026 | FixPoint Security
The Defensive Line Weekly #40: 20–27 September 2026 | FixPoint Security

ShinyHunters' renewed exploitation campaign underscores the significant risk of unpatched Oracle PeopleSoft environments. Organizations relying on this software must prioritize deploying the security patch released in June 2026 without delay. Attempts to rely solely on WAF rules or mitigations are insufficient, as attackers can bypass these defenses.

Effective patching combined with proactive monitoring and credential management will materially reduce exposure to this serious vulnerability and prevent costly data breaches or extortion incidents.

React to this story

Related Posts