CVE-2026-35280 -- CVSS 9.9 Vulnerability Briefing
CVE-2026-35280 | CVSS 9.9 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-35280 is a critical-severity vulnerability in Oracle WebCenter Enterprise Capture, a component of Oracle Fusion Middleware, specifically affecting the Client Bundle component in versions 12.2.1.4.0 and 14.1.2.0.0.
Technical Detail
The vulnerability is described as easily exploitable, which based on Oracle's standard advisory language typically indicates that an attacker with network access and low or no authentication requirements can trigger the flaw without user interaction. The affected Client Bundle component represents a network-accessible attack surface within the Oracle Fusion Middleware stack. With a CVSS score of 9.9, the vulnerability likely enables high-impact outcomes such as remote code execution or complete compromise of confidentiality, integrity, and availability on the affected system, though the truncated description does not confirm the precise exploitation mechanism.
Exploitation Status
No known exploit has been observed or documented for this vulnerability as of June 24, 2026. It is not listed in the CISA Known Exploited Vulnerabilities catalog. There is no public proof-of-concept code confirmed at this time. Despite the absence of known exploitation, the critical CVSS score and Oracle's characterization of the flaw as easily exploitable warrant treating this as a high-priority patching target.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this CVE in available intelligence sources as of the date of this briefing.
What To Do
Apply Oracle's patch for WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 as released through Oracle's Critical Patch Update cycle. Given the 9.9 CVSS score and the easily exploitable characterization, organizations running either affected version should prioritize patching on an emergency basis rather than waiting for a standard maintenance window. Where immediate patching is not feasible, restrict network access to the Client Bundle component using perimeter controls or host-based firewall rules to limit exposure to trusted hosts only. Monitor for anomalous activity originating from or targeting WebCenter Enterprise Capture services, including unexpected outbound connections or privilege changes on the hosting system. Verify patch application by confirming the updated version string post-deployment.