CVE-2026-35309 -- CVSS 9.8 Vulnerability Briefing
CVE-2026-35309 | CVSS 9.8 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-35309 is a critical-severity vulnerability in Oracle Coherence, a component of Oracle Fusion Middleware, specifically affecting the Centralized Third Party Jars component across multiple supported versions including 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0.
Technical Detail
The vulnerability originates in a third-party library bundled within Oracle Coherence, a pattern that frequently introduces deserialization, remote code execution, or authentication bypass flaws depending on the upstream component involved. Given the CVSS score of 9.8 and the network-accessible attack surface typical of Coherence deployments, the flaw is likely exploitable remotely without authentication, potentially enabling full system compromise or arbitrary code execution on affected middleware hosts. The precise technical mechanism has not been fully disclosed in available public advisories, but the critical rating and affected component class are consistent with unauthenticated RCE or a similarly severe impact class.
Exploitation Status
No known exploit code has been identified as of June 24, 2026. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog, and no proof-of-concept or operational exploit has been publicly confirmed. Organizations should not interpret the absence of known exploitation as an indicator of low urgency given the CVSS 9.8 score and the historically high targeting of Oracle Fusion Middleware components.
Who Is Targeting This
No confirmed threat actor attribution has been established for this CVE at this time. Reported (research-inferred, medium confidence): DEEPPANDA, CARBANAK, LOTUSBLOSSOM, AXIOM, and MOONSTONESLEET have been associated with this vulnerability in threat intelligence reporting, though none of these attributions have been independently verified and motivations remain unknown. These actors span a range of suspected origins and operational profiles, and their inclusion should be treated as preliminary research inference rather than confirmed targeting.
What To Do
Apply Oracle's patch for CVE-2026-35309 as part of the relevant Oracle Critical Patch Update cycle with high priority, prioritizing internet-facing or externally accessible Coherence deployments first. Versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 are confirmed affected and should be patched without delay. Where immediate patching is not feasible, restrict network access to Coherence cluster ports and management interfaces using firewall rules or network segmentation to reduce the exposed attack surface. Monitor for anomalous deserialization activity, unexpected outbound connections from middleware hosts, and unusual process spawning from Java runtime processes as potential indicators of exploitation attempts. Verify that no third-party jar components within the Coherence deployment have been independently modified or replaced outside of official Oracle distribution channels.