CVE-2026-35298 -- CVSS 9.1 Vulnerability Briefing
CVE-2026-35298 | CVSS 9.1 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-35298 is a critical vulnerability in the Core component of Oracle WebLogic Server, affecting versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, that is described as easily exploitable by unauthenticated remote attackers.
Technical Detail
The flaw resides in the Core component of Oracle WebLogic Server and can be triggered remotely without authentication, indicating a network-accessible attack surface with no credential requirement. Based on the CVSS score of 9.1 and the "easily exploitable" characterization, the vulnerability likely enables remote code execution or significant unauthorized access to sensitive data or system resources. Full technical specifics regarding the precise flaw class, such as deserialization, SSRF, or authentication bypass, have not been publicly disclosed at this time.
Exploitation Status
No known exploit has been publicly documented as of June 24, 2026. This vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and no proof-of-concept code or operational exploit has been confirmed. Given the critical severity rating and Oracle WebLogic's historical profile as a high-value target, the absence of a known exploit should not be interpreted as low risk.
Who Is Targeting This
No confirmed, ATTAX-verified threat actor attribution exists for this CVE at this time. Reported associations at medium confidence include DEEPPANDA, CARBANAK, LOTUSBLOSSOM, AXIOM, and MOONSTONESLEET, though these attributions are research-inferred and have not been independently verified. Motivations for all reported actors are currently unknown. These associations should be treated as preliminary intelligence pending further corroboration.
What To Do
Organizations running Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0 should apply Oracle's available patches as a priority, treating this as an urgent remediation given the critical CVSS score and unauthenticated remote exploitability. Where immediate patching is not feasible, restrict network access to WebLogic administrative and T3/IIOP ports using firewall rules or network segmentation to limit exposure. Monitor WebLogic server logs for anomalous deserialization activity, unexpected outbound connections, or unusual process spawning from the WebLogic process. Oracle's Critical Patch Update advisory for this CVE should be consulted for vendor-specific patch guidance and any interim workarounds.