BoletimSec•September 28, 2026•🇵🇹Translated from Portuguese

Mandiant Uncovers WAF Bypass Campaign Exploiting Critical Oracle PeopleSoft CVE-2026-35273

Mandiant has identified an ongoing campaign exploiting CVE-2026-35273, a critical vulnerability in Oracle PeopleSoft with a CVSS score of 9.8. The flaw resides in the Environment Management Hub, known as PSEMHUB, and enables unauthenticated remote code execution.

The distinctive element of this wave is a simple web application firewall bypass that depends on a single character. Attackers substitute the path /PSEMHUB/ with /%50SEMHUB/, where %50 represents the URL encoding of the letter P. Many WAF and reverse-proxy rules compare the literal path before decoding the URL, while the PeopleSoft application server decodes the request and forwards it to the vulnerable servlet.

Exploitation and Web Shell Deployment

Exploitation occurs through Java object deserialization. Attackers send specially crafted POST requests to /%50SEMHUB/hub containing serialized Java objects. Successful exploitation results in the installation of two JSP web shells inside the PSEMHUB.war directory.

  • x.jsp executes operating-system commands across multiple platforms.
  • u.jsp supports chunked file uploads and execution via cmd.exe.

Persistence and Tooling

Following initial access, the operators deploy a trojanized installer named Ple64.exe that loads the SIDEEYE backdoor. They additionally install the Neo-reGeorg tunneling tool and the remote administration framework MeshAgent. Approximately one quarter of observed commands were executed with root or SYSTEM privileges.

The activity is attributed to UNC6240, a group linked to ShinyHunters. The campaign began as a zero-day targeting educational institutions in June 2026 and has since expanded to higher education, technology, healthcare, agriculture, transportation, and government organizations. No Oracle patch is referenced in the current analysis.

Related articles

Hispasec•Vulnerabilities & Exploits

CISA Sets September 30 Deadline for Federal Agencies to Patch Actively Exploited Citrix NetScaler Zero-Days

CISA has ordered U.S. federal agencies to apply patches by September 30 for two actively exploited zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, enable unauthenticated remote code execution under default configurations and affect systems commonly exposed to the internet. CVE-2026-88771 allows remote code execution without authentication on NetScaler ADC and Gateway, while CVE-2026-88772 can trigger remote code execution or denial of service via a memory overflow when DTLS is enabled on VPN vServers. Citrix has released fixes for versions 14.1 and 13.1, including FIPS and NDcPP builds, with minimum required builds of 14.1-73.37 and 13.1-64.23. The advisory also covers six additional vulnerabilities from CVE-2026-88773 to CVE-2026-88778 involving HTTP request smuggling and TCP ISN prediction issues. Unsupported branches NetScaler 12.1 and 13.0 receive no patches, requiring immediate migration. Organizations are advised to inventory instances, check for compromise indicators before patching, and preserve forensic evidence.

BoletimSec•Vulnerabilities & Exploits

CSRF Flaw in Elementor Allows Admin Account Creation on Over 2 Million WordPress Sites

A critical CSRF vulnerability has been identified in the Elementor page builder plugin for WordPress, affecting versions 4.3.0 and 4.3.1. The issue enables attackers to create administrator accounts on target sites by exploiting improper handling of CSRF protections in the Editor Events module. With a CVSS score of 8.8, the flaw impacts more than 2 million installations out of over 10 million total WordPress sites using the plugin. No CVE identifier had been assigned at the time of disclosure on September 26. The vulnerability was fixed in version 4.3.2, and users are urged to update immediately. The discovery is credited to researcher Saggre following responsible disclosure, with no public records of active exploitation noted at the time of analysis.

Habr•Vulnerabilities & Exploits

Dissecting CVE-2026-83557 in jackson-databind: Why Not Every CVE Requires Immediate Panic

A detailed analysis of CVE-2026-83557 reveals that the vulnerability in jackson-databind affects only a narrow set of configurations involving polymorphic deserialization with the Comparable base type. The flaw stems from an incomplete denylist in DefaultBaseTypeLimitingValidator, which overlooks java.lang.Comparable when the MapperFeature.BLOCK_UNSAFE_POLYMORPHIC_BASE_TYPES flag is explicitly enabled. Researchers constructed working proof-of-concept exploits showing that an attacker can instantiate classes such as java.io.File, but only when the property is declared as Comparable<?> and the protective flag is active. The issue impacts versions 2.11 through 2.22.1, yet the CVSS score of 5.6 reflects its moderate real-world risk because most applications lack the required Comparable-typed polymorphic fields. Patching introduces its own trade-off by blocking legitimate Comparable subclasses, forcing developers to implement custom BasicPolymorphicTypeValidator allowlists. The case highlights how dependency scanners often flag CVEs without considering application-specific configuration and DTO structures.

Security NEXT•Vulnerabilities & Exploits

Multiple Critical Vulnerabilities Found in Citrix NetScaler ADC and Gateway, Two Actively Exploited

Cloud Software Group disclosed eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway products on September 27, 2026. Two of the issues, CVE-2026-88771 and CVE-2026-88772, have already been confirmed as exploited in the wild, prompting urgent remediation advice. CVE-2026-88771 stems from insufficient input validation and allows unauthenticated remote code execution across all default configurations. CVE-2026-88772 involves a memory overflow that can lead to code execution or denial of service when DTLS is enabled, which occurs by default on VPN vServers. The remaining six vulnerabilities cover code execution, denial of service, and HTTP request smuggling risks, with the advisory rated Critical overall. Organizations are urged to apply patches immediately and investigate potential breaches.