Trend Micro
Read post

PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM

A critical pre-authentication RCE chain (CVE-2026-35273, CVSS 9.8) in Oracle PeopleSoft PeopleTools 8.61 and 8.62 exploits the PSIGW Integration Broker gateway via SSRF to reach the internal PSEMHUB management servlet, then achieves code execution through Java XMLDecoder deserialization on web-tier restart. The chain is notably stealthy: execution occurs inside the WebLogic JVM with no child process spawned and no outbound beacon, making conventional behavioral and network detection ineffective. Oracle issued an out-of-band patch on June 10, 2026, but exploitation was observed in the wild from May 27 by threat actor SHADOW-AETHER-015 (ShinyHunters) targeting over 100 organizations. Post-exploitation options include JSP web shell deployment and NetNTLM credential coercion via SMB. Defenders are advised to patch immediately, restrict PSIGW network exposure, monitor envmetadata/ filesystem paths, and treat web-tier restarts as security-relevant events.

    #security#java
Jun 19•12m read time•From trendmicro.com
Post cover image
330 Impressions
Trend Micro's image
Trend Micro

Trend Micro Blog offers insights, analysis, and updates on cybersecurity threats, trends, and best p...

75 Followers

•

72 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard