Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-35305 -- CVSS 9.3 Vulnerability Briefing

CVE-2026-35305 | CVSS 9.3 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-35305 is a critical vulnerability in Oracle Coherence, a component of Oracle Fusion Middleware, specifically affecting the Centralized Third Party Jars component in version 15.1.1.0.0, and is described as easily exploitable by unauthenticated remote attackers.

Technical Detail

The flaw resides in the Centralized Third Party Jars component of Oracle Coherence 15.1.1.0.0, indicating a vulnerable or misconfigured third-party library bundled within the product. Based on the CVSS score of 9.3 and the "easily exploitable" characterization, an unauthenticated network-adjacent or remote attacker can likely trigger the vulnerability with low complexity and no required privileges, potentially resulting in remote code execution or significant unauthorized data access. The full technical description is truncated in available data, so the precise exploitation mechanism and complete impact chain have not been publicly confirmed at this time.

Exploitation Status

No known exploit has been observed or documented as of June 24, 2026. This vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, and no proof-of-concept code has been publicly confirmed. The absence of known exploitation does not reduce the urgency of remediation given the critical CVSS score and the easily exploitable characterization.

Who Is Targeting This

No confirmed threat actor attribution has been established for this CVE. Reported (research-inferred, medium confidence): DEEPPANDA, CARBANAK, LOTUSBLOSSOM, AXIOM, and MOONSTONESLEET have been associated with this vulnerability in threat intelligence reporting, though origin and motivation details are not available for any of these actors in current data. These associations should be treated as preliminary and not as confirmed operational targeting.

What To Do

Organizations running Oracle Coherence 15.1.1.0.0 should apply Oracle's patch for this vulnerability as a priority, treating the critical CVSS score and easy exploitability as the primary drivers for urgency. Monitor Oracle's Critical Patch Update advisories for the official patch release and apply it within your standard critical patch SLA, or sooner if Oracle Coherence is internet-facing or accessible to untrusted network segments. Until patching is complete, restrict network access to Oracle Coherence services using firewall rules or network segmentation to limit exposure to trusted hosts only. Review logs for anomalous deserialization activity, unexpected class loading, or unusual outbound connections from Coherence nodes as potential indicators of exploitation attempts.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →