• Sources: report
  • Summary: The group requests /%50SEMHUB/ instead of /PSEMHUB/, so a WAF rule matching the literal endpoint string does not fire while the application server decodes the path and serves the request, which invalidates the endpoint-blocking mitigation Mandiant recommended in June for CVE-2026-35273. Mandiant advises operators to search WebLogic access logs for both forms and states the actual fix is the Oracle security update rather than any WAF rule, while Google warns the group may switch to other percent-encoded or mixed-case variants. Affected PeopleSoft versions are not stated in the available reporting, and Mandiant's own report URL did not resolve, so the detail here comes from BleepingComputer quoting it, which is why this sits last in Top stories on a single source.
  • Why it matters: Any defence that pattern matches a request path before the application server decodes it can be stepped around by encoding one character, so operators who blocked an endpoint at the WAF instead of patching CVE-2026-35273 are exposed again.

send feedback on this story