Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-35308 -- CVSS 10.0 Vulnerability Briefing

CVE-2026-35308 | CVSS 10.0 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-35308 is a critical-severity vulnerability in Oracle Coherence, a component of Oracle Fusion Middleware, specifically affecting the Centralized Third Party Jars component across multiple supported versions including 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0.

Technical Detail

The vulnerability resides in a third-party library bundled within Oracle Coherence, a distributed caching and in-memory data grid platform commonly deployed in enterprise Java environments. The precise flaw class has not been fully disclosed in available public advisories, but the CVSS score of 10.0 indicates a remotely exploitable, unauthenticated attack vector with no required user interaction and full impact across confidentiality, integrity, and availability, consistent with unauthenticated remote code execution. Successful exploitation would likely allow an attacker to execute arbitrary code in the context of the Coherence server process, potentially compromising the underlying host and any connected data infrastructure.

Exploitation Status

As of June 24, 2026, no known exploit code has been publicly observed or confirmed. This vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploit maturity is currently assessed as none, meaning no proof-of-concept or operational exploit has been documented in open or closed sources at this time. Given the maximum CVSS score and the nature of the affected component, this should be treated as high-priority for patching regardless of current exploitation status.

Who Is Targeting This

No confirmed threat actor attribution has been established for this vulnerability. Reported associations at medium confidence include DEEPPANDA, CARBANAK, LOTUSBLOSSOM, AXIOM, and MOONSTONESLEET; however, these attributions are research-inferred and have not been independently verified or operationally confirmed. No motivations have been identified for any of the reported actors in relation to this specific CVE. These associations should be treated as preliminary indicators only and not used as the sole basis for threat modeling decisions.

What To Do

Organizations running Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, or 14.1.2.0.0 should apply Oracle's patch as soon as it becomes available through the Oracle Critical Patch Update cycle, treating this as an emergency priority given the CVSS 10.0 rating. Until patching is complete, administrators should restrict network access to Coherence cluster ports and management interfaces using perimeter controls and host-based firewall rules, limiting exposure to trusted internal networks only. Monitoring for anomalous process execution, unexpected outbound connections, or unusual class loading activity on Coherence nodes is advisable as a detection measure. Organizations should also audit their inventory for any internet-facing deployments of Oracle Coherence and prioritize those instances for immediate isolation or remediation.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →