CVE-2026-35307 -- CVSS 10.0 Vulnerability Briefing
CVE-2026-35307 | CVSS 10.0 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-35307 is a critical unauthenticated remote code execution vulnerability in the Core component of Oracle Coherence, a distributed caching and data grid product within the Oracle Fusion Middleware stack, affecting versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Technical Detail
The flaw resides in the Core component of Oracle Coherence and is described by Oracle as easily exploitable, meaning an unauthenticated attacker with network access can trigger the vulnerability without requiring user interaction or elevated privileges. Based on the CVSS 10.0 score and the affected component, successful exploitation likely results in full remote code execution on the underlying host, granting the attacker complete control over the affected system. The attack vector is network-accessible, which significantly broadens the exposure surface for any Coherence instance reachable from untrusted networks.
Exploitation Status
No known exploit code has been publicly documented as of June 24, 2026, and this CVE is not currently listed in the CISA Known Exploited Vulnerabilities catalog. There is no confirmed in-the-wild exploitation at this time. However, the combination of a CVSS 10.0 score and Oracle's own characterization of the flaw as easily exploitable means the window between disclosure and weaponization is likely to be short.
Who Is Targeting This
No confirmed, ATTAX-verified threat actor attribution exists for this vulnerability at this time. Reported (research-inferred): Five threat actors have been associated with this CVE at medium confidence -- DEEPPANDA, CARBANAK, LOTUSBLOSSOM, AXIOM, and MOONSTONESLEET. These attributions are research-inferred and have not been independently confirmed. Motivations for each actor are currently unknown. No active campaigns leveraging this vulnerability have been documented.
What To Do
Apply Oracle's patch for CVE-2026-35307 immediately, prioritizing any Coherence instance exposed to untrusted or internet-facing networks. Affected versions are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 -- all should be updated to the patched release provided in Oracle's Critical Patch Update advisory. Where immediate patching is not feasible, restrict network access to Coherence cluster ports using firewall rules or network segmentation to limit exposure to trusted hosts only. Monitor for anomalous outbound connections, unexpected process spawning from Coherence service accounts, and unusual deserialization activity in application logs. Given the CVSS 10.0 rating and the ease-of-exploitation characterization, treat this as a priority-one patch cycle item regardless of current KEV status.