Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-35263 -- CVSS 9.9 Vulnerability Briefing

CVE-2026-35263 | CVSS 9.9 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-35263 is a critical-severity vulnerability in Oracle WebLogic Server's Core component, affecting versions 14.1.2.0.0 and 15.1.1.0.0, that allows unauthenticated remote attackers to compromise the server.

Technical Detail

The flaw resides in the Core component of Oracle WebLogic Server and is classified as easily exploitable, meaning no specialized conditions or user interaction are required to trigger it. Based on the CVSS score of 9.9 and the characterization of the vulnerability, the likely impact includes unauthenticated remote code execution or near-complete system compromise, potentially affecting confidentiality, integrity, and availability of the underlying host. The full technical mechanism has not been publicly disclosed in the available description, but the severity rating and exploitability classification indicate a low-complexity attack path accessible over the network without credentials.

Exploitation Status

No known exploit has been publicly documented for this vulnerability as of June 24, 2026. It is not listed in CISA's Known Exploited Vulnerabilities catalog, and no proof-of-concept code has been confirmed in open sources. Despite the absence of confirmed exploitation, the critical CVSS score and easily exploitable classification make this a high-priority patching target before exploit code emerges.

Who Is Targeting This

No confirmed threat actor attribution has been established for this CVE. Reported associations at medium confidence include DEEPPANDA, CARBANAK, LOTUSBLOSSOM, AXIOM, and MOONSTONESLEET, based on research-inferred intelligence rather than verified operational activity against this specific vulnerability. The origin and motivation for each of these actors is not specified in available reporting. These associations should be treated as contextual indicators only and not as confirmed targeting of CVE-2026-35263.

What To Do

Organizations running Oracle WebLogic Server versions 14.1.2.0.0 or 15.1.1.0.0 should apply Oracle's patch for this vulnerability immediately, prioritizing internet-facing and production deployments. This CVE is not currently subject to a CISA binding directive, but the critical severity and unauthenticated attack vector justify treating it as an emergency patch. If patching cannot be applied immediately, restrict network access to WebLogic administrative ports and the Core component interfaces using perimeter controls and host-based firewall rules. Monitor WebLogic server logs for anomalous deserialization activity, unexpected outbound connections, or process spawning from the WebLogic JVM process, which are common indicators of exploitation in similar WebLogic vulnerabilities. Verify patch application against Oracle's official advisory and confirm version currency after deployment.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →