Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-35282 -- CVSS 9.9 Vulnerability Briefing

CVE-2026-35282 | CVSS 9.9 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-35282 is a critical-severity vulnerability in Oracle WebCenter Enterprise Capture, specifically within the Client Bundle component, affecting versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle Fusion Middleware.

Technical Detail

The flaw is described as easily exploitable, which in Oracle's advisory language indicates that an attacker requires minimal conditions or privileges to trigger the vulnerability. Based on the CVSS score of 9.9 and the affected component (Client Bundle), the vulnerability likely permits remote code execution or significant unauthorized access, potentially allowing a low-privileged network-adjacent or remote attacker to compromise the host system or escalate privileges within the Fusion Middleware environment. Full technical specifics regarding the precise attack vector and payload mechanism have not been publicly disclosed beyond Oracle's advisory language at this time.

Exploitation Status

No known exploit has been observed or documented as of June 24, 2026. This vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog. No proof-of-concept code has been publicly confirmed. Despite the absence of known exploitation, the critical CVSS score and Oracle's characterization of the flaw as easily exploitable warrant treating this as a high-priority patching target.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with CVE-2026-35282 in available intelligence sources as of this writing.

What To Do

Apply Oracle's patch for WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 as released through Oracle's Critical Patch Update cycle. Given the CVSS score of 9.9 and the ease-of-exploitation characterization, this should be treated as an immediate patching priority rather than deferred to a standard maintenance window. Organizations unable to patch immediately should restrict network access to the WebCenter Enterprise Capture Client Bundle interface, enforce strict firewall rules to limit exposure to trusted hosts only, and monitor application and network logs for anomalous access patterns targeting the affected component. Verify patch application through Oracle's provided remediation guidance and confirm version currency post-deployment.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →