Google threat researchers have reported renewed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft. The campaign modifies earlier exploit traffic so that requests can bypass web application firewall rules that match the vulnerable path as a literal string.
Encoded paths can defeat narrow filtering rules
The reported requests substitute an encoded character in the PeopleSoft Environment Management Hub path. A proxy or WAF may inspect the request before decoding it, while the application server later normalizes the path and routes it to the vulnerable servlet. The mismatch shows why an edge rule is not a substitute for applying Oracle’s security update.
Google linked the renewed activity to UNC6240 and observed web-shell deployment on affected systems. Reported targets span education, technology, healthcare, transportation and government. Post-exploitation activity can include command execution, credential theft, tunneling and data staging.
Defenders need patching and host-level review
Organizations should apply the vendor fix, review whether the Environment Management Hub service is required and search access logs for encoded variants of the vulnerable path. PeopleSoft and WebLogic hosts should be inspected for unexpected JSP files, remote-management tools, archives and unusual outbound connections.
The campaign reinforces the need for layered controls in Cyber-Physical Security. Teams should rotate credentials accessible to the application account and preserve logs before cleanup. A WAF can reduce exposure, but application patching, host monitoring and identity recovery remain necessary when attackers change request encoding.

Leave a Reply