Critical Oracle PeopleSoft Flaw (CVE-2026-35273) Actively Exploited by UNC6240 to Deploy Backdoors
A renewed mass-exploitation campaign is targeting Oracle PeopleSoft Environment Management Hub servers through CVE-2026-35273, a critical unauthenticated remote-code-execution vulnerability with a CVSS score of 9.8. Google tracks the activity to UNC6240, a threat actor linked to ShinyHunters, and said attackers modified the exploit to bypass web application firewall rules before deploying web shells, backdoors and tunneling tools across multiple sectors. ShinyHunters separately claimed it compromised the U.S. FBIJobs.gov portal and stole about 2 to 3 TB of data, but those claims came from the actor.
Key Points
- UNC6240 resumed mass exploitation of the PeopleSoft PSEMHUB servlet in September 2026 after modifying its exploit to evade WAF rules.
- The attack uses URL-encoded paths, serialized Java objects and Java deserialization to obtain unauthenticated remote code execution.
- Attackers installed JSP web shells, the SIDEEYE backdoor, Neo-reGeorg and MeshAgent for execution, tunneling and persistence.
- Targets included higher education, technology, IT services, healthcare, agriculture, transportation and government organizations.
- Oracle issued an emergency update on June 10, and defenders should patch, disable or remove the Environment Management Hub and hunt for the listed indicators.
Renewed exploitation
Google’s Mandiant and Google Threat Intelligence Group (GTIG) observed the renewed campaign in September 2026, with activity reported on September 22. The earlier zero-day exploitation window ran from May 27 through June 9 and included attacks against academic institutions. Oracle issued an emergency security update for CVE-2026-35273 on June 10.
Mandiant and GTIG described the reason the campaign resumed:
“This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint.”
Mandiant and Google Threat Intelligence Group
Mandiant said it notified more than 100 organizations whose IP addresses matched vulnerable endpoints, most of them in the United States. Separate reporting identified web shells on dozens of compromised systems across higher education, technology, IT services, healthcare, agriculture, transportation and government environments.
Exploit chain and malware
CVE-2026-35273 affects the PeopleSoft Environment Management Hub servlet and allows unauthenticated remote code execution through Java deserialization. Attackers sent POST requests containing serialized Java objects to /%50SEMHUB/hub, encoding the letter P as %50 instead of using the literal /PSEMHUB/ path.
The encoding bypassed many string-based WAF and reverse-proxy rules that inspected the literal path before URL decoding. PeopleSoft decoded the request and routed it to the vulnerable servlet. Mandiant and GTIG described the technique:
“The threat actor bypassed these string-based WAF rules by URL-encoding a single character in the request path… Many WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet.”
Mandiant and Google Threat Intelligence Group
The resulting fileless command execution allowed the attackers to place JSP web shells in the PSEMHUB.war directory. The x.jsp shell provided cross-platform command execution, while u.jsp supported chunked file uploads and command execution, including through cmd.exe.
The attackers also staged a signed, trojanized installer named Ple64.exe, approximately 5.2 MB in size. The installer loaded the SIDEEYE C++ backdoor into memory. SIDEEYE supports browser and desktop-application credential theft, file and process management, an interactive reverse shell and reverse-proxy functions.
Other tools included the Neo-reGeorg tunneling toolkit and MeshAgent, a legitimate remote-management tool deployed for persistence on Linux systems. About 25% of observed commands ran as root or NT AUTHORITY\SYSTEM; the remaining commands ran under PeopleSoft or WebLogic service accounts. An external host at 162.219.30[.]165 was identified as a SIDEEYE server.
Lateral movement and data theft
UNC6240 used SSH to move between internal PeopleSoft systems, relying on known username and password combinations and scripts that connected to additional machines. The activity also included staging tunneling tools, using in-memory backdoors and minimizing visible artifacts such as the size of the web shells.
Attackers issued bulk queries and exports against HR, payroll and student records. Mandiant said the activity matched UNC6240’s established data-theft extortion pattern:
“UNC6240 has a well-established pattern of data theft extortion, that is, stealing data and threatening to release it on a data leak site unless the victim pays a ransom.”
Mandiant and Google Threat Intelligence Group
ShinyHunters claimed that it compromised the FBIJobs.gov portal and stole approximately 2 to 3 TB of data. A ShinyHunters spokesperson denied that the activity involved extortion:
“We want to reiterate and emphasise that we are NOT extorting the FBI… This is NOT financially motivated. This is NOT a ransom or extortion. All we seek to do is set the record straight and protect the image of our organisation.”
ShinyHunters spokesperson
Recommendation
Organizations running PeopleSoft should install Oracle’s June 10 emergency update for CVE-2026-35273 rather than relying only on WAF rules. Oracle’s recommended configuration changes include disabling the Environment Management Hub service in multi-server deployments or removing the PSEMHUB application entirely from single-server deployments.
Defenders should review WebLogic and web-server access logs for requests to /PSEMHUB/ and encoded variants such as /%50SEMHUB/. They should inspect PSEMHUB.war and related web directories for x.jsp, u.jsp and other unexpected JSP files; rotate credentials readable by PeopleSoft service accounts; and investigate credentials reused for SSH access.
Additional checks should cover large archive files in temporary or web-accessible directories, database audit logs showing bulk exports of HR, payroll or student records, and outbound connections from PeopleSoft hosts to 162.219.30[.]165 or other anomalous destinations. Organizations should remove unauthorized MeshAgent deployments and Neo-reGeorg instances, use inline IPS signatures, apply zero-trust segmentation or microsegmentation to limit lateral movement, and enforce egress policies that can detect or disrupt large-scale data exfiltration.