News

Attackers Bypass WAFs With a Single Character to Exploit Critical Oracle PeopleSoft Flaw

A new campaign against CVE-2026-35273 shows why perimeter defenses can't be your only line of protection while you patch.

Attackers Bypass WAFs With a Single Character to Exploit Critical Oracle PeopleSoft Flaw

Threat actors are actively exploiting a critical Oracle PeopleSoft vulnerability, CVE-2026-35273 (CVSS 9.8), and they are getting past Web Application Firewalls with one URL-encoded character.

PSEMHUB was never meant to be reached from the outside world. It sits behind an IP allow-list, and the original exploit chain reached it indirectly: attackers abused PeopleSoft’s unauthenticated Integration Broker listening connector to make the server issue a loopback request to itself, satisfying that allow-list from the inside. Since disclosure, many organizations have added a WAF rule blocking direct external requests to /PSEMHUB/ as a compensating control. According to Google’s Mandiant, the ShinyHunters-linked group tracked as UNC6240 found that rule is trivial to evade. The attackers request /%50SEMHUB/ instead of /PSEMHUB/. %50 is simply the encoded form of the letter “P”. Many WAF and reverse proxy rules match the literal request path before decoding it. The PeopleSoft application server decodes the request and sends it straight to the vulnerable servlet, no SSRF hop required.

Once past the perimeter, the attackers abuse Java deserialization in the PSEMHUB hub servlet. They then drop JSP web shells, achieve fileless command execution, and install backdoors and remote management tools for persistence. Mandiant reports web shells on dozens of systems across higher education, technology, healthcare, government, transportation, and other sectors. About a quarter of the attackers’ commands ran with root or SYSTEM privileges.

The Patching Gap Is the Real Risk

Relying on WAFs to buy time for patching is a risky game. While your security and development teams prepare, test, and deploy a source code patch, your applications stay exposed. As this campaign shows, a string-based perimeter rule can be defeated by the simplest encoding trick.

There is a better way.

Protection From the Inside Out

Waratek RASP doesn’t try to catch obfuscated malicious traffic at the perimeter. It protects your applications from within the runtime. Waratek’s runtime rules block attacks against known and Zero Day vulnerabilities, even when a WAF has been completely bypassed.

Here is how Waratek stops this attack chain:

Deserialization Rule. CVE-2026-35273 depends on sending a malicious serialized Java object to the PSEMHUB hub. Waratek’s runtime security rule strictly controls Java deserialization and neutralizes the malicious payload before it can compromise the application.

Process Forking Controls. If an attacker tries to use a web shell to run system commands, Waratek’s process forking rules block unauthorized OS command execution. This stops backdoors and fileless attacks cold.

Encoding Tricks Don’t Matter at Runtime

Waratek operates at the runtime layer, so it doesn’t matter how many encoding tricks an attacker uses to slip past the WAF. The malicious action is blocked the moment it tries to execute inside the application.

This shifts the balance of power back to defenders. It prevents exploitation of both known CVEs and Zero Day flaws, and it gives your security teams the breathing room they need to test and deploy source code patches safely.

Stop relying on perimeter defenses for application-layer flaws. Secure your runtime instead.

Read more about the Oracle PeopleSoft WAF bypass campaign on The Hacker News.

About Waratek

Waratek offers Waratek IAST+RASP, the only compiler-based, runtime application tools that find vulnerabilities in the pre-production development pipeline, block attacks in production, and virtually patch flaws with no downtime or source code changes. Waratek IAST watches code execute to identify security flaws with absolute certainty, eliminating the “guesswork” and alert fatigue associated with traditional scanners. Waratek RASP intercepts and terminates unsafe operations at the JVM level, stopping attempts to change app behavior in attacks aimed at known and Zero Day vulnerabilities. Waratek is a trusted partner for organizations in global financial services, hospitality, healthcare, technology and other industries. Waratek has offices in Dublin, Ireland and Chicago, Illinois.

Share Article