Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-35270 -- CVSS 9.1 Vulnerability Briefing

CVE-2026-35270 | CVSS 9.1 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-35270 is a critical vulnerability in Oracle WebCenter Content, specifically within the Content Server component, affecting versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle Fusion Middleware.

Technical Detail

The flaw is described by Oracle as easily exploitable, indicating low attack complexity and no requirement for elevated privileges or user interaction to trigger. Based on the CVSS score of 9.1 and the affected component, the vulnerability likely enables an unauthenticated or low-privileged attacker to achieve unauthorized access, data exposure, or remote code execution against the Content Server. The high severity rating suggests significant impact to confidentiality, integrity, or availability of the affected system.

Exploitation Status

No known exploit code has been publicly identified at this time. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. While no active exploitation has been confirmed, the "easily exploitable" classification from Oracle indicates a low barrier to weaponization, which increases the risk of rapid exploit development once the vulnerability receives broader attention.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this CVE as of June 24, 2026.

What To Do

Apply Oracle's patch for affected versions 12.2.1.4.0 and 14.1.2.0.0 as part of Oracle's standard Critical Patch Update cycle. Given the critical CVSS score of 9.1 and the easily exploitable classification, patching should be treated as high priority and not deferred to routine maintenance windows. Organizations running Oracle WebCenter Content that are internet-facing or accessible from untrusted networks should prioritize immediate remediation. If patching cannot be applied immediately, restrict network access to the Content Server component using firewall rules or network segmentation to limit exposure. Monitor Content Server access logs for anomalous authentication attempts or unexpected API calls as a detection measure pending patch deployment.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →