Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-35301 -- CVSS 10.0 Vulnerability Briefing

CVE-2026-35301 | CVSS 10.0 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-35301 is a critical unauthenticated remote code execution vulnerability affecting the Console component of Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0, part of the Oracle Fusion Middleware product family.

Technical Detail

The flaw resides in the WebLogic Server administrative Console and is described as easily exploitable by an unauthenticated remote attacker over the network, requiring no user interaction or prior privileges. Based on the CVSS 10.0 score and the "easily exploitable" characterization, successful exploitation likely enables full remote code execution or complete system compromise on the affected server. The combination of network accessibility, no authentication requirement, and maximum severity score indicates that an attacker with access to the Console port can achieve arbitrary code execution or equivalent impact without any preconditions.

Exploitation Status

No known exploit has been publicly documented as of June 24, 2026. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog, and no proof-of-concept or operational exploit code has been confirmed. However, the trivial exploitation conditions and maximum CVSS score make this a high-priority target for exploit development, and the absence of a known exploit should not be interpreted as low urgency.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with CVE-2026-35301 in available intelligence sources as of this writing.

What To Do

Apply Oracle's patch for this vulnerability immediately, prioritizing any internet-facing or externally reachable WebLogic Console instances running versions 12.2.1.4.0 or 14.1.1.0.0. If patching cannot be completed immediately, restrict network access to the WebLogic Console port (typically TCP 7001 and 7002) using firewall rules or network segmentation, limiting access to trusted administrative hosts only. Organizations should audit whether the WebLogic Console is exposed to untrusted networks and disable it entirely if administrative access is not required. Monitor for anomalous HTTP requests targeting the Console endpoint and review WebLogic access logs for unexpected authentication attempts or unusual request patterns. Given the maximum severity rating and ease of exploitation, this vulnerability should be treated as patch-priority one regardless of current exploitation status.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →