CVE-2026-35301 -- CVSS 10.0 Vulnerability Briefing
CVE-2026-35301 | CVSS 10.0 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-35301 is a critical unauthenticated remote code execution vulnerability affecting the Console component of Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0, part of the Oracle Fusion Middleware product family.
Technical Detail
The flaw resides in the WebLogic Server administrative Console and is described as easily exploitable by an unauthenticated remote attacker over the network, requiring no user interaction or prior privileges. Based on the CVSS 10.0 score and the "easily exploitable" characterization, successful exploitation likely enables full remote code execution or complete system compromise on the affected server. The combination of network accessibility, no authentication requirement, and maximum severity score indicates that an attacker with access to the Console port can achieve arbitrary code execution or equivalent impact without any preconditions.
Exploitation Status
No known exploit has been publicly documented as of June 24, 2026. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog, and no proof-of-concept or operational exploit code has been confirmed. However, the trivial exploitation conditions and maximum CVSS score make this a high-priority target for exploit development, and the absence of a known exploit should not be interpreted as low urgency.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with CVE-2026-35301 in available intelligence sources as of this writing.
What To Do
Apply Oracle's patch for this vulnerability immediately, prioritizing any internet-facing or externally reachable WebLogic Console instances running versions 12.2.1.4.0 or 14.1.1.0.0. If patching cannot be completed immediately, restrict network access to the WebLogic Console port (typically TCP 7001 and 7002) using firewall rules or network segmentation, limiting access to trusted administrative hosts only. Organizations should audit whether the WebLogic Console is exposed to untrusted networks and disable it entirely if administrative access is not required. Monitor for anomalous HTTP requests targeting the Console endpoint and review WebLogic access logs for unexpected authentication attempts or unusual request patterns. Given the maximum severity rating and ease of exploitation, this vulnerability should be treated as patch-priority one regardless of current exploitation status.