Threat reportVulnerabilityTL-2026-1094

Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day (CVE-2026-35273) Exploited by ShinyHunters (UNC6240)

criticalACTIVE

Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day (TL-2026-1094), also tracked as PeopleSoft PSEMHUB Zero-Day, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-03 and last reviewed 2026-09-27. It is attributed to UNC6240 with high confidence, affects Oracle PeopleSoft Enterprise PeopleTools, references 3 CVEs (CVE-2026-35273, CVE-2026-35278, CVE-2026-35271), maps to 35 MITRE ATT&CK techniques (T1016, T1018, T1021), and is covered by 9 detection rules and 45 indicators of compromise.

CVSS
9.8/10Critical
CVEs
3Referenced vulnerabilities
Techniques
35MITRE ATT&CK
Actors
1UNC6240
Detection rules
9SPL · KQL · Sigma
IOCs
45Indicators of compromise

Key facts for TL-2026-1094

Threat ID
TL-2026-1094
Also known as
PeopleSoft PSEMHUB Zero-Day, PSIGW SSRF-to-RCE Chain, PeopleSoft Environment Management Hub RCE
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution
UNC6240
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
education, higher education, automotive, international-organizations, government administration
Target regions
North America, Europe, Asia-Pacific, united kingdom
Detection rules
9
Indicators of compromise
45
Updates
2026-09-27 · 3 updates · revalidated 2× · latest source

Malware and tooling in Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day

Malware and tooling: MeshCentral

How Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day works

CVE-2026-35273 (CVSS 9.8) is a pre-authentication remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools 8.61/8.62, in which the unauthenticated /PSEMHUB/hub endpoint deserializes attacker-controlled Java objects via XMLDecoder, reachable through an SSRF chain in the /PSIGW/HttpListeningConnector Integration Broker gateway. The financially motivated extortion group UNC6240 (ShinyHunters) exploited it as a zero-day from May 27 to June 9, 2026, compromising 300+ PeopleSoft instances at 100+ organizations (68% higher education) before Oracle's June 10, 2026 out-of-band patch and the June 12, 2026 CISA KEV addition.

CVE-2026-35273 affects the Updates Environment Management (EMHub/PSEMHUB) component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 (earlier unsupported versions are likely also affected). The PeopleSoft web tier co-hosts the Integration Broker gateway (/PSIGW/HttpListeningConnector) and the Environment Management Hub (/PSEMHUB/hub) without requiring authentication on either. An attacker posts a crafted XML envelope (a DOCTYPE external-entity reference, an EnvironmentManagement message, or an IBRequest SOAP message) whose sourceURL/url/HubURL element points at an attacker-controlled or loopback (127.0.0.1) target. Because the Integration Broker does not validate that submitted XML documents avoid referencing internal or external network resources, it acts as an unauthenticated SSRF proxy, relaying the request to the local Hub. The Hub's /PSEMHUB/hub handler then treats the value of the OPERATION POST parameter as a serialized Java object and deserializes it via XMLDecoder before any authentication check occurs, allowing arbitrary Java object instantiation from classes already present on the PeopleSoft classpath (a gadget chain of legacy XML-deserialization primitives combined with a zero-day logic flaw that bypasses input validation). Published exploitation invokes Hub operations such as FILECHUNKING, REGISTER_WITHOUT_PEERNAME, and HANDLE_MESSAGE to achieve remote code execution inside the PSEMHUB WebLogic JVM process, running as the PeopleSoft application-server OS user (commonly 'psoft').

Google Mandiant assessed that UNC6240 (publicly self-identifying as ShinyHunters, and increasingly operating under the federated 'Scattered Lapsus$ Hunters' brand alongside Scattered Spider and LAPSUS$-linked actors) exploited CVE-2026-35273 as a zero-day for approximately two weeks -- May 27 to June 9, 2026 -- before Oracle's advisory. At 22:14 UTC on May 27, 2026 the actor stood up a customized MeshCentral (v1.1.59) open-source remote monitoring and management server on staging infrastructure to serve as a command-and-control hub; eleven minutes later (22:25 UTC) they installed the 'acme-client' npm package to automatically provision Let's Encrypt TLS certificates for a masquerade domain, azurenetfiles.net, styled to resemble Microsoft's legitimate Azure NetApp Files service. Compiled Windows MeshCentral agent binaries (meshagent32-azure-ops.exe / meshagent64-azure-ops.exe) were staged to call back to wss://azurenetfiles.net:443/agent.ashx. Five sequential staging IPs (142.11.200.186-190) ran exposed Python SimpleHTTPServer instances on TCP/8888, publicly listing attacker tooling and shell/command history.

Post-exploitation activity included harvesting database and application credentials from the psappsrv.cfg PeopleSoft application-server configuration file, then using the uon_fanout.sh shell script to spray those credentials (targeting the psoft, oracle, and linuxadm accounts, with SSH-key fallback if password auth failed) against internal hosts enumerated from /etc/hosts, enabling lateral movement across PeopleSoft server tiers. Collected data was compressed with zstd prior to exfiltration over an outbound SSH connection to infrastructure hosting a public mirror of the ShinyHunters Tor leak site (176.120.22.24). Compromised hosts were defaced with a marker file, README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT, dropped into WebLogic and Process Scheduler directories, alongside recently modified XML files consistent with XMLDecoder-based persistence.

UNC6240/ShinyHunters ran a 'pay-or-leak' extortion model -- no ransomware encryption was deployed; victims retained system access throughout, with leverage instead coming from the threat of publishing stolen data. Mandiant notified more than 100 organizations whose internet-facing systems matched vulnerable PeopleSoft endpoints; 68% were higher-education institutions, predominantly in the United States. Confirmed named victims include the University of Nottingham (UK, with campuses in Malaysia and China), from which roughly 40GB covering an estimated 454,600-500,000 current and former student records was published on June 9, 2026 after the university declined to pay; the Council of Europe, whose data was claimed on June 14, 2026 with a June 16 ransom deadline, resulting in publication of a 297GB claimed dataset (payroll records for 10,000+ employees from 2011-2026, 14,000+ CVs, HR/Secretariat/Parliamentary Assembly files); and Nissan Americas, which filed breach notifications on June 25, 2026 (publicly reported June 29, 2026) after employee PII -- SSNs, Social Insurance Numbers, National Identification Numbers, banking details, and tax/financial records for staff in the US, Canada, Mexico, and Brazil -- was exposed.

Oracle published a security alert and out-of-band emergency patch for CVE-2026-35273 on June 10, 2026. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on June 12, 2026, with a federal remediation deadline of July 3, 2026. Trend Micro's Zero Day Initiative/Trend Research and multiple vendors (Rapid7, Qualys, Arctic Wolf, SOCRadar) published independent technical and detection guidance in the following weeks.

MITRE ATT&CK techniques used in TL-2026-1094

Discovery

T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1082 System Information Discovery; T1087 Account Discovery

Lateral Movement

T1021 Remote Services; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

Exfiltration

T1048 Exfiltration Over Alternative Protocol

Execution

T1059 Command and Scripting Interpreter; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1059.004 Command and Scripting Interpreter: Unix Shell

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1573 Encrypted Channel

Credential Access

T1187 Forced Authentication; T1552 Unsecured Credentials; T1552.001 Unsecured Credentials: Credentials In Files

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1491 Defacement; T1657 Financial Theft

Persistence

T1505 Server Software Component; T1505.003 Server Software Component: Web Shell

Collection

T1560 Archive Collected Data

Resource Development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities; T1588.002 Obtain Capabilities: Tool; T1608 Stage Capabilities

Reconnaissance

T1595 Active Scanning; T1595.002 Active Scanning: Vulnerability Scanning; T1596.003 Search Open Technical Databases: Digital Certificates; T1596.005 Search Open Technical Databases: Scan Databases

Affected products and versions in Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day

  • Oracle — PeopleSoft Enterprise PeopleTools
    Vulnerable versions: 8.61; 8.62; earlier unsupported PeopleTools releases (likely affected)
    Fixed in: 8.61 with June 10, 2026 Oracle out-of-band Security Alert patch; 8.62 with June 10, 2026 Oracle out-of-band Security Alert patch

Remediation for Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day

Patches

  • Oracle out-of-band Security Alert patch for CVE-2026-35273, released June 10, 2026, for PeopleTools 8.61 and 8.62

Immediate actions

  • Apply Oracle's June 10, 2026 out-of-band emergency patch for CVE-2026-35273 without waiting for the standard Critical Patch Update cycle
  • Block external/internet access to /PSEMHUB/* and /PSIGW/HttpListeningConnector at the network perimeter and WAF
  • Disable the Environment Management Hub (EMHub) service in multi-server configurations, or remove the PSEMHUB application entirely in single-server configurations
  • Assume compromise for any internet-facing PeopleTools 8.61/8.62 instance exposed between May 27 and June 10, 2026 and initiate forensic review
  • Hunt for README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT, unexpected .jsp files under PSEMHUB.war/, and recently modified XML files on PeopleSoft hosts
  • Rotate credentials referenced in psappsrv.cfg (database, psoft, oracle, linuxadm) and review SSH authorized_keys across all PeopleSoft-tier hosts

Workarounds

  • Disable/remove the Environment Management Hub (PSEMHUB) service where patching cannot be applied immediately
  • Block external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector via firewall/WAF rules

Longer-term hardening

  • Deploy EDR/behavioral monitoring on all PeopleSoft application, web, and process scheduler tiers
  • Segment PeopleSoft server tiers from general internal network access to reduce lateral-movement blast radius
  • Implement egress filtering/monitoring for outbound SSH, websocket, and SMB traffic from PeopleSoft servers to untrusted external destinations
  • Establish a vulnerability-driven emergency patching process for internet-facing ERP components
  • Deploy detection for unauthorized RMM tools (e.g., MeshCentral) on production application servers

CVEs associated with Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day

CVE-2026-35273, CVE-2026-35278, CVE-2026-35271

Weaknesses (CWE) in Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day

CWE-306, CWE-918, CWE-502

Timeline of Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day

Showing the 20 most recent tracked events.

  • At 22:25 UTC, attackers install the acme-client npm package to auto-provision Let's Encrypt TLS certificates for the azurenetfiles[.]net masquerade domain used as the MeshCentral C2 endpoint.
  • At 22:14 UTC, attackers install a customized MeshCentral v1.1.59 server on staging infrastructure to serve as command-and-control for post-exploitation access.
  • UNC6240 (ShinyHunters) begins exploiting CVE-2026-35273 as an undisclosed zero-day against internet-facing Oracle PeopleSoft /PSEMHUB/hub endpoints.
  • Active zero-day exploitation window closes; UNC6240 has by this point compromised 300+ PeopleSoft instances across 100+ organizations, 68% in higher education.
  • ShinyHunters publishes roughly 40GB of University of Nottingham data covering an estimated 454,600-500,000 current and former students on its leak site after the university declines to pay.
  • Oracle publishes an out-of-band Security Alert advisory and emergency patch for CVE-2026-35273 covering PeopleTools 8.61 and 8.62.
  • Mandiant/Google Threat Intelligence publishes a report attributing the May 27-June 9 zero-day exploitation to UNC6240 (ShinyHunters) and notifying 100+ affected organizations.
  • CISA adds CVE-2026-35273 to the Known Exploited Vulnerabilities catalog, setting a federal civilian remediation deadline of 2026-07-03.
  • ShinyHunters claims theft of Council of Europe HR/payroll data (297GB claimed, 429,000+ files) and issues a ransom deadline of 2026-06-16.
  • After the Council of Europe's ransom deadline passes, ShinyHunters publishes a 4.7GB compressed dataset from the claimed breach, including payroll records for 10,000+ employees spanning 2011-2026.
  • Oracle's June 2026 Critical Security Patch Update (10 critical / 67 CVEs) ships an additional, unauthenticated remotely-exploitable Oracle Supply Chain patch.
  • Qualys ThreatPROTECT publishes detection and defense guidance for the PSEMHUB authentication bypass chain.
  • Nissan Americas files data breach notifications after determining employee PII (SSNs, SINs, banking and tax records) across the US, Canada, Mexico, and Brazil was exposed via the CVE-2026-35273 campaign.
  • Nissan's PeopleSoft-linked employee data breach is publicly reported by security media.
  • Earlier intrusions observed across May-July 2026 deploy unencrypted MeshAgent binaries and configuration files (meshagent, meshagent.msh, meshagent.db) in /tmp on compromised Linux PeopleSoft hosts, using Microsoft-masquerading domains for cover.
  • Oracle releases its largest-ever Critical Patch Update (1449 patches / 1235 unique CVEs across 32 product families), formally fixing the related PeopleSoft pre-auth RCE sibling CVE-2026-35278 and priv-esc/RCE chain CVE-2026-35271.
  • AusCERT publishes bulletin ASB-2026.0162 ('Oracle Supply Chain'), referencing the July 2026 Oracle CPU; the bulletin itself is member-gated with no public mirror available.
  • ShinyHunters publicly claims a breach of 'FBI Systems,' consistent with the group's ongoing pattern of data-theft extortion operations.
  • Google Cloud/Mandiant publishes a report on ShinyHunters' renewed mass-exploitation campaign, disclosing the percent-encoding WAF-bypass technique, new IOCs (SIDEEYE backdoor, winmanage-me.network infrastructure), and expanded sector targeting.
  • BleepingComputer publishes reporting on the /%50SEMHUB/ percent-encoding WAF-bypass technique, warning that WAF mitigations alone are insufficient without patching.

Update history for TL-2026-1094

Sources cited for Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day

Detection coverage for TL-2026-1094

As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1094 across Splunk SPL, Microsoft KQL and Sigma, covering 45 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
45 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-1094

6 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats