Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-35286 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-35286 | CVSS 9.8 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-35286 is a critical unauthenticated vulnerability in Oracle WebCenter Content, specifically within the Content Server component, affecting versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle Fusion Middleware.

Technical Detail

The flaw is described by Oracle as "easily exploitable" and carries a CVSS score of 9.8, indicating a network-accessible attack vector requiring no authentication and no user interaction. Based on the severity profile and the nature of the Content Server component, successful exploitation likely enables remote code execution or complete compromise of the affected server. Full technical details regarding the specific flaw class, such as deserialization, SQL injection, or path traversal, have not been publicly disclosed at this time.

Exploitation Status

No known exploit has been publicly documented or observed as of June 24, 2026. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. The absence of a known exploit does not reduce the urgency of patching given the critical CVSS score and the unauthenticated, network-accessible attack surface.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this CVE in available intelligence sources.

What To Do

Apply Oracle's patch for WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 immediately, prioritizing any internet-facing or externally accessible Content Server deployments. Organizations should treat this as a high-priority patch given the unauthenticated, network-exploitable nature of the vulnerability. If patching cannot be completed immediately, restrict network access to the Content Server component using firewall rules or network segmentation to limit exposure to trusted internal hosts only. Monitor Content Server logs for anomalous access patterns, unexpected process spawning, or unusual outbound connections as potential indicators of exploitation attempts.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →