The ShinyHunters-linked threat cluster UNC6240 has renewed mass exploitation of Oracle PeopleSoft servers vulnerable to CVE-2026-35273. The critical flaw affects Oracle PeopleSoft Enterprise PeopleTools and allows unauthenticated remote code execution. Attackers have expanded their targeting beyond higher-education organizations to technology, healthcare, government, transportation, agriculture, and IT services. Oracle rates the vulnerability with a CVSS score of 9.8 and warns that successful exploitation can result in takeover of the PeopleSoft environment. UNC6240 has modified its exploitation technique to bypass web application firewall protections by using URL-encoded paths instead of directly requesting the vulnerable PSEMHUB endpoint. Mandiant observed POST requests containing serialized Java objects, followed by deployment of JSP web shells after successful exploitation. The attackers also used tools for credential theft, command execution, reverse shells, tunneling, and remote management. Compromise can expose PeopleSoft configuration files, database credentials, Integration Broker credentials, and cloud secrets, particularly where application processes have elevated privileges. Organizations should immediately apply Oracle's security update for CVE-2026-35273 and should not rely on WAF rules as a substitute for patching. Where applicable, administrators should disable the Environment Management Hub or remove the PSEMHUB application according to Oracle guidance. Security teams should review WebLogic and PIA logs for encoded or abnormal PSEMHUB requests, inspect application archives for unauthorized JSP/JSPX files, investigate suspicious processes, and rotate credentials accessible to the PeopleSoft application tier.
A newly demonstrated security flaw in LibreOffice and Apache OpenOffice shows how seemingly legitimate spreadsheet features can be combined to execute malicious code without the us...
Four vulnerabilities disclosed in Apache Struts could expose affected applications to remote code execution, denial of service, resource exhaustion, and cross-user data disclosure....
Atlassian has disclosed a critical arbitrary file access vulnerability, CVE-2026-21589, affecting Jira Software Data Center and Confluence Data Center. Rated CVSS 9.3, the flaw all...