The Patch Was There. The Attack Came Back.
ABRI Systems ·
Incident timing: September 2026 campaign; publicly reported . Exact start date of the renewed wave was not disclosed.
In September 2026, hackers broke into systems running Oracle PeopleSoft, software that organizations use to manage employee records, payroll and other business information. Security researchers reported that dozens of systems were affected. The attackers gained access that could let them control the servers and reach information stored there.
The weakness they exploited was already known. Oracle had released a security update in June, but some organizations had relied on another protective measure instead of installing it.
That protection was supposed to block suspicious requests before they reached the software. In September, the attackers changed how they wrote those requests and got past it. Because the software had not been updated, the original weakness was still there.
The lesson is straightforward: a temporary protection can reduce the danger, but it does not remove the problem. This incident shows how that distinction can leave sensitive business and employee information at risk.
How the attackers bypassed the firewall rules
A web application firewall, or WAF, checks requests before they reach an application. Here, some rules looked for the literal path /PSEMHUB/. Attackers sent /%50SEMHUB/ instead. The sequence %50 represents the letter P.
The filter missed the spelling; the application decoded it and reached the same vulnerable component. This disagreement over how to read a request is the technical lesson. Mandiant’s analysis
Why the software update still matters
A firewall rule can reduce exposure while a team schedules maintenance, tests an update or resolves a dependency. That is useful work. But the task should remain open until the underlying problem is addressed and the result is verified.
Mitigation reduces risk. Remediation addresses the cause. A temporary control needs an owner, a review date and a clear definition of what “finished” means.
For PeopleSoft operators, Oracle’s security alert identifies affected PeopleTools versions and links installation guidance. Follow the vendor instructions for your environment. Patching also does not establish whether someone already gained access; that requires investigation.
The broader lesson applies to any emergency workaround. When the immediate pressure fades, the permanent fix still needs a place on the calendar. Otherwise, the next change in attacker behaviour can expose the same unfinished job.
Sources checked October 5, 2026: Mandiant / GTIG, September 25 report; Oracle security alert. Analogies and workflow advice are ABRI Systems’ analysis.
Security tip: give every workaround an expiry date.
Today, choose one vulnerability marked “mitigated.” Record the affected systems, the person responsible for the permanent fix, and a firm review date. Keep it open until you have evidence that the vendor fix was applied to every affected instance and validated.
If you operate PeopleSoft, use Mandiant’s remediation checklist for compromise checks alongside the patch work. A quiet alert queue is not proof that the vulnerability is gone.