CVE-2026-35304 -- CVSS 9.8 Vulnerability Briefing
CVE-2026-35304 | CVSS 9.8 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-35304 is a critical unauthenticated remote code execution vulnerability in the Core component of Oracle Coherence, a distributed caching and data grid product within the Oracle Fusion Middleware stack.
Technical Detail
The flaw exists in the Core component of Oracle Coherence and affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Oracle's advisory characterizes the vulnerability as easily exploitable, meaning an unauthenticated attacker with network access can trigger the flaw without requiring user interaction or elevated privileges. Successful exploitation could result in full compromise of the affected Coherence instance, with potential for remote code execution and unauthorized control over data managed by the cluster.
Exploitation Status
No known exploit code has been publicly identified or confirmed as of June 24, 2026. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog. Despite the absence of confirmed exploitation, the critical CVSS score of 9.8 and Oracle's own characterization of the flaw as easily exploitable indicate a low barrier to weaponization once technical details become more widely available.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this CVE as of the date of this briefing.
What To Do
Apply Oracle's patch for CVE-2026-35304 as part of the relevant Oracle Critical Patch Update cycle with high priority, given the critical severity rating and the ease-of-exploitation characterization. Organizations running Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0 should treat patching as urgent. Where immediate patching is not feasible, restrict network access to Coherence cluster ports using firewall rules or network segmentation to limit exposure to trusted hosts only. Monitor Coherence service logs and network traffic for anomalous connection attempts or unexpected serialization activity, which may indicate reconnaissance or exploitation attempts against the Core component.