Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-35300 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-35300 | CVSS 9.8 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-35300 is a critical unauthenticated remote code execution vulnerability in the Core component of Oracle WebLogic Server, affecting versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.

Technical Detail

The flaw resides in the Core component of Oracle WebLogic Server and is described as easily exploitable by an unauthenticated attacker with network access, requiring no user interaction. The vulnerability likely involves a deserialization or T3/IIOP protocol weakness consistent with the WebLogic Core attack surface, allowing a remote attacker to execute arbitrary code on the underlying server with the privileges of the WebLogic process. Successful exploitation results in full compromise of the affected server, including potential lateral movement into connected Oracle Fusion Middleware infrastructure.

Exploitation Status

No known exploit has been publicly documented as of June 24, 2026. This CVE is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Despite the absence of confirmed exploitation, the CVSS score of 9.8 and the "easily exploitable" classification indicate low barrier to exploitation once a working method is developed or disclosed. Organizations should treat this as high-priority patching regardless of current exploit maturity.

Who Is Targeting This

No specific threat actor attribution at this time. No confirmed or research-inferred threat actor activity has been associated with this CVE as of the publication date. It should be noted that Oracle WebLogic Server vulnerabilities historically attract attention from financially motivated actors and state-sponsored groups, but no such association has been established for this specific vulnerability.

What To Do

Apply Oracle's patch for CVE-2026-35300 immediately across all affected WebLogic Server versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) via the Oracle Critical Patch Update process. If patching cannot be completed immediately, restrict network access to WebLogic administration ports and T3/IIOP endpoints at the perimeter and host-based firewall level, limiting exposure to trusted internal networks only. Monitor for anomalous outbound connections, unexpected process spawning from the WebLogic JVM process, and unusual deserialization activity in application logs. Verify that WebLogic administrative consoles are not exposed to the public internet. Given the critical CVSS rating and ease-of-exploitation designation, this vulnerability should be treated as an emergency patch priority.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →