The WAF Rule Was a String Match
On June 10, 2026, Oracle released an out-of-band Security Alert for CVE-2026-35273, an unauthenticated remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools 8.61 and 8.62, carrying a CVSS 3.1 base score of 9.8. Mandiant’s June guidance for organizations that could not patch or disable the component immediately was to block external access to the vulnerable /PSEMHUB/* path at the perimeter. That was a sensible fallback. It was also a published string.
On September 25, Mandiant and Google Threat Intelligence Group reported that UNC6240, the group tracked elsewhere as ShinyHunters, had resumed mass exploitation. The renewals were not against unmanaged servers. They were against servers whose operators had applied the perimeter block and skipped the patch.
The entire bypass is one percent-encoded character. Requests went to /%50SEMHUB/ instead of /PSEMHUB/.
Nothing was defeated. The path was respelled.
The bug, in one paragraph
The affected component is Updates Environment Management, and the vulnerable surface is the Environment Management Hub servlet. Exploitation abuses Java deserialization in the PSEMHUB hub servlet: a POST to /hub carrying a serialized Java object produces code execution without credentials. Oracle scores it Network / Low complexity / No privileges / No user interaction, with High confidentiality, integrity, and availability impact. The alert credits Bobby Gould of TrendAI Zero Day Initiative, Lucas Miller of TrendAI Research, and Minh Giang of TrendAI Zero Day Initiative. Oracle’s independent advisory record and several national advisories repeat the 9.8 score.
Before the patch, this was a zero-day. Mandiant observed the June wave between May 27 and June 9, notified more than 100 exposed organizations, and found 68 percent of them in higher education. Oracle fixed it on June 10. The interim control was a path block.
Two decodes, one decision
The bypass is not a parsing trick that finds a bug in WebLogic. WebLogic is behaving correctly by its own rules. The failure is that two components make the same routing decision from two different spellings of the same path, and the control sits on the wrong side of the decode.
June guidance: block /PSEMHUB/* at the perimeter
September request: POST /%50SEMHUB/hub (%50 is "P")
WAF rule match: literal /PSEMHUB -> no match, request allowed
WebLogic: decodes the path -> routes to the PSEMHUB servlet
Mandiant states the split exactly: many WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet. %50 is the encoded form of P. The rule that was supposed to be a boundary never saw the string it was written against.
The uncomfortable second-order effect is detection. If your alerting is keyed on the same literal /PSEMHUB/ that your blocking rule is keyed on, then the moment an attacker respells the path you lose both the block and the visibility, from the same rule, at the same layer. Mandiant’s remediation list makes the point by implication: search PIA WebLogic access logs for requests to /PSEMHUB/ and any percent-encoded variant, especially POST requests to /hub and requests to .jsp files from external source IPs. Compare on the normalized path. Do not assume the attacker stuck to %50; Mandiant warns that any percent-encoded, mixed-case, or otherwise non-normalized variant of the path should be assumed reachable.
What the campaign looks like on the host
The renewed campaign opens quietly. Targets typically receive five to 15 POST requests to /%50SEMHUB/hub carrying a serialized Java object. On an unpatched server these return the host operating system in the response, with no file written and no service disruption. That is a cheap exploitability check, and on hosts the actor validated but did not yet use, it may be the only trace you have.
Exploitation then takes one of two paths, both Java deserialization against the same servlet:
- Web shell deployment. Bursts of
POSTrequests to/%50SEMHUB/hub, followed by new JSP files in thePSEMHUB.wardirectory, such asx.jsp, or sequentially numbered variants. The repetition is deliberate: it is aimed at making sure every node behind a load balancer receives a copy. Checking only the node you found first is not an inventory. - Fileless command execution.
POSTrequests to/%50SEMHUB/hubthat return command output directly in the HTTP response, with nothing written to disk. On the host this appears ascmd.exeor/bin/shprocesses spawned by the WebLogic Java process. Mandiant is explicit that detections relying on JSP file creation will not catch this method.
Once in, the tooling is careful about the same class of matching that let them in. The primary shell, x.jsp, accepts hex-encoded commands in a POST parameter rather than cleartext commands in a query string, detects the operating system, and on Linux reconstructs /bin/sh from an ASCII character array (47,98,105,110,47,115,104) to avoid static string signatures. A companion shell, u.jsp, writes Base64 file chunks in 150 KB increments to stay under request size limits and bypass PeopleSoft’s native FILECHUNKING handlers, with a variant u2.jsp in the observed set.
On Windows the staging binary is Ple64.exe, 5.2 MB, masquerading as a signed Light Alloy media player installer. It is a trojanized installer carrying a three-stage chain that loads a VMProtect 3 protected second stage and then the SIDEEYE C++ backdoor in memory, which talks to its command and control server over raw TCP on separate control (3333) and data (3334) ports. The analyzed sample was signed with a valid Extended Validation certificate issued to a software development entity through Sectigo; Mandiant says it has contacted Sectigo for revocation. For lateral movement the actor dropped the open source Neo-reGeorg toolkit as tunnel.jsp and tunnel.jspx, tunnelling SOCKS5 over ordinary HTTP and HTTPS from the web tier. For Linux persistence, it deployed MeshAgent, the legitimate MeshCentral remote management agent, including through domains built to look like Microsoft property.
Across compromised instances, a quarter of the observed commands ran as root or NT AUTHORITY\SYSTEM. The remainder ran under PeopleSoft or WebLogic service accounts, which is still enough to reach PeopleSoft configuration files, database connection strings, and application data.
Here is the symmetry worth keeping: the defenders’ control matched a literal string, and the attacker’s own tooling went out of its way to avoid literal strings. x.jsp refuses to contain the word it executes. The rule that guarded the front door would not have recognized the shell either.
What the intuition gets wrong
The intuition is that a compensating control buys time, and it does. What it does not do is change who owns the window.
Mandiant’s June post published the interim guidance, including the perimeter path block. The September post says plainly that UNC6240 adapted to published defensive guidance and targeted organizations that applied the WAF rule without patching. That is the honest reading of the timeline: the mitigation told the attacker which string to change, and the string was one character long. This is not a failure of the WAF vendor or the operator. It is what happens when the fallback control and the attack surface are the same string, matched at different times, by different components, with different decoding rules.
The second intuition is that a blocked path means reduced exposure. It did not reduce the exposure. It reduced the attacker’s inconvenience, and it removed the operator’s reason to keep the patch on the calendar. The servers that got hit were not forgotten. They were closed out.
What is claimed, and what is not
This part is allegation, and it should be labeled as such.
On September 22, BleepingComputer reported that ShinyHunters claimed to have breached FBI systems using what the group described as a new Oracle PeopleSoft zero-day, allegedly gaining access to internal services before moving laterally into FBI managed AWS GovCloud infrastructure, and allegedly stealing between 2TB and 3TB of data covering current and former employees, job applicants, and other internal records. The group allegedly defaced the FBI Jobs site, and the publication said it was shown a screenshot of the claimed defacement. 404 Media separately reported receiving a sample of roughly 5,000 purported employee records and said it verified that some of the information, including phone numbers, was consistent with real people and Department of Justice personnel. The FBI told BleepingComputer it was investigating unauthorized activity affecting fbijobs.gov and did not confirm a breach or a data theft. BleepingComputer stated it could not independently verify the alleged zero-day, the lateral movement, or the amount of data.
The detail that matters for this post is the follow-up. In the September 26 story, ShinyHunters confirmed to BleepingComputer that it had used the %50 bypass against FBI Jobs, while continuing to claim a separate, unknown vulnerability in the same PSEMHUB component. Take both claims as unverified. Then note what they leave us with: on one reading, the agency’s exposure was the same unpatched endpoint reached by the same respelled path; on the other, there is a second deserialization bug in the same servlet that has not been published. Either way the common denominator is an exposed Environment Management Hub, and the operator response is identical. That is the useful property of this kind of gossip. The story is unconfirmed, and the remediation does not depend on it.
The operator consequence
- Normalize before you match. Enforce decisions on the decoded path, not the literal bytes in the request line. Treat any encoding ambiguity at the edge as a defect in the control, because the application server will decode it and route it anyway.
- Do not let the edge be the boundary. Mandiant’s own remediation list leads with the patch and states directly that WAF rules and path-based blocking are not a substitute for patching. A perimeter rule is a detection and delay mechanism. It is not a fix, and it does not close at the origin.
- Remove the capability where you cannot patch. The guidance is to disable the EMHub service in multi-server configurations, or remove the PSEMHUB application entirely in single-server configurations. EMHub is administrative and system to system. It does not need to be reachable from the internet, and if you do not use it for patching, it does not need to be running.
- Separate your detection from your mitigation. Search access logs for the normalized path and for encoded variants, for
POSTrequests to/hub, and for.jsprequests from external source IPs. Watch processes as well as files, because fileless execution by the WebLogic Java process leaves no new file behind for a file creation rule to find. - Inventory the war directory on every node.
PSEMHUB.warforx.jsp,u.jsp,u2.jsp,tunnel.jsp,tunnel.jspx, andPle64.exe. Check all load balanced nodes, not the first one that answers. - Rotate what the service account could read. Database connection strings in
psappsrv.cfg, Integration Broker credentials, and any cloud credentials reachable from the web tier. A patch applied after a compromise does not undo the credentials that were already read. - A valid signature is not provenance. The staging binary carried an EV certificate issued through a commercial CA. Treat signed as unknown until you know who signed it and why it is on a middleware server.
The thesis
A control whose match key is the attacker’s spelling is a control the attacker co-authors. The %50 bypass did not find a flaw in the WAF, the reverse proxy, or WebLogic. It found a boundary enforced one layer above where the decision is actually made, and it moved the decision down a layer by changing one character in a URL.
The boundary that closed this incident was the June 10 patch, at the origin, where the bug lived. Everything else was a delay with a published key. If the only thing standing between your middleware and an unauthenticated deserialization bug is a literal string match, you are not mitigated. You are scheduled.
Sources:
- ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft, Mandiant and Google Threat Intelligence Group, Sep 25, 2026 (primary: the
/%50SEMHUB/bypass mechanism and the pre-decoding literal match, target verification with 5 to 15 POST requests, web shell versus fileless execution,x.jsp,u.jsp,u2.jspand the ASCII array reconstruction of/bin/sh,Ple64.exeand SIDEEYE with the EV certificate detail and C2 ports 3333 and 3334, Neo-reGeorgtunnel.jsp, MeshAgent persistence, the quarter of commands running as root or SYSTEM, the example encoded request line, and the full remediation list) - ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant, Jun 11, 2026 (primary: the May 27 to June 9 zero-day window, more than 100 organizations notified with 68 percent in higher education, the June interim guidance to block external access to
/PSEMHUB/*, and the assessment that WAF body inspection alone was insufficient) - Oracle Security Alert Advisory, CVE-2026-35273, Oracle, initial release Jun 10, 2026 (primary: affected versions 8.61 and 8.62, the Updates Environment Management component, unauthenticated remote exploitation over HTTP, and the CVSS 3.1 vector scoring 9.8)
- ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks, BleepingComputer, Sep 26, 2026 (secondary: the
%50encoding restated, the statement that ShinyHunters confirmed using the bypass against FBI Jobs while still claiming a separate unknown vulnerability, and the deployment set ofx.jsp,u.jspandu2.jsp) - ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach, BleepingComputer, Sep 22, 2026 (secondary, and the source of the alleged material above, including the 2TB to 3TB claim, the alleged defacement, the FBI statement, and the explicit note that BleepingComputer did not independently verify the zero-day, the lateral movement, or the data volume)
- Cyber Security Agency of Singapore advisory AL-2026-072, CVE-2026-35273 (secondary: independent restatement of the CVSS 9.8 score and the actively exploited status)
- @DarkWebInformer on X, Sep 25, 2026 (discovery source for this run; quotes Mandiant’s finding that the new campaign targets organizations that attempted to mitigate the flaw with WAF rules but did not install the patch, and reports the deployed toolset; 301 likes, 20,663 views at capture)