CuraSec

tag: Waf-Bypass · 1 items

2026-09-26 · Google Threat Intelligence · source ↗ #oracle-peoplesoft#waf-bypass#active-exploitation
  • Engineer — Act: CVE-2026-35273 is CISA KEV-listed with active mass exploitation and a public PoC; WAF rules blocking /PSEMHUB/ are bypassed by the URL-encoded path /%50SEMHUB/, meaning appliances that appeared mitigated may still be exposed — patch PeopleSoft immediately, update WAF rules to match post-decode paths, and audit PSEMHUB access logs for web shell drops going back to June 2026.
  • SOC/IR — Act: UNC6240 is deploying web shells at scale across healthcare, government, tech, and other sectors; hunt web server logs for requests to /%50SEMHUB/ or other URL-encoded variants of the PSEMHUB path, sweep PeopleSoft systems for new or modified files consistent with web shell staging, and treat any PeopleSoft exposure prior to patching as assume-breach.
  • Leader — Act: Named threat actor is conducting cross-sector mass exploitation with a bypass that defeats the most common mitigation; if your organization runs Oracle PeopleSoft, confirm exposure status with your engineering team this week, assess whether the June–September window created undetected compromise, and brief leadership given the breadth of affected sectors including healthcare and government.
  • Signals: CVE-2026-35273 — CISA KEV: listed, EPSS 0.09, public PoC on GitHub, reported by 2 collected sources