Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-35306 -- CVSS 9.3 Vulnerability Briefing

CVE-2026-35306 | CVSS 9.3 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-35306 is a critical-severity vulnerability in Oracle Coherence, a component of Oracle Fusion Middleware, specifically affecting the Centralized Third Party Jars component in version 15.1.1.0.0, and is described as easily exploitable by unauthenticated or low-privilege attackers.

Technical Detail

The flaw resides in a third-party library bundled within Oracle Coherence 15.1.1.0.0, a distributed caching and in-memory data grid platform. The vulnerability is classified as easily exploitable, suggesting that an attacker with network access and minimal prerequisites can trigger the flaw without complex preconditions, potentially achieving remote code execution or significant unauthorized access to affected systems. The full technical mechanism has not been publicly disclosed beyond Oracle's advisory language, but the CVSS score of 9.3 indicates high impact across confidentiality, integrity, and availability dimensions.

Exploitation Status

No known exploit code has been identified at this time, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog. Exploit maturity is currently assessed as none, meaning no public proof-of-concept or operational exploit has been confirmed. This status should be monitored closely given the critical severity rating and the ease-of-exploitation characterization in the advisory.

Who Is Targeting This

No confirmed threat actor attribution has been established for this vulnerability. Reported associations at medium confidence include DEEPPANDA, CARBANAK, LOTUSBLOSSOM, AXIOM, and MOONSTONESLEET; however, these are research-inferred associations and should not be treated as confirmed targeting of this specific CVE. Origin and motivation details for all reported actors are currently unknown. These associations warrant monitoring but do not constitute verified intelligence of active exploitation by any named group.

What To Do

Organizations running Oracle Coherence 15.1.1.0.0 should apply Oracle's patch for this vulnerability as part of the relevant Oracle Critical Patch Update cycle without delay, prioritizing systems exposed to untrusted networks or internet-facing deployments. Until patching is complete, restrict network access to Oracle Coherence services using firewall rules or network segmentation to limit exposure to trusted hosts only. Monitor Oracle's official security advisories for any updates to affected version scope or additional mitigation guidance. Given the ease-of-exploitation rating and critical CVSS score, this should be treated as a high-priority remediation item even in the absence of confirmed active exploitation.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →