Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-35312 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-35312 | CVSS 9.8 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-35312 is a critical-severity vulnerability in Oracle Virtual Directory, a component of Oracle Fusion Middleware, affecting the Virtual Directory Server subcomponent in versions 12.2.1.4.0 and 14.1.2.0.0.

Technical Detail

The vulnerability is described as easily exploitable, a characterization Oracle uses in its CPU advisories to indicate low attack complexity and no requirement for prior authentication or user interaction. Based on the CVSS score of 9.8 and the affected component, the flaw likely permits unauthenticated remote code execution or complete compromise of the Virtual Directory Server process. Successful exploitation would give an attacker the ability to read, modify, or delete data managed by the directory service, and potentially pivot to connected identity infrastructure.

Exploitation Status

No known exploit exists for this vulnerability as of June 24, 2026. It is not listed in the CISA Known Exploited Vulnerabilities catalog. There is no public proof-of-concept code or confirmed in-the-wild exploitation at this time. Given the critical CVSS score and the network-accessible attack surface, this should be treated as a high-priority patching target regardless of current exploitation status.

Who Is Targeting This

No confirmed threat actor attribution has been established for this vulnerability. Reported associations at medium confidence include DEEPPANDA, CARBANAK, LOTUSBLOSSOM, AXIOM, and MOONSTONESLEET; however, these are research-inferred associations and have not been independently verified through direct operational evidence. No motivation or origin data is available for these reported actors in relation to this specific CVE. Attribution should not be treated as confirmed pending further corroboration.

What To Do

Apply Oracle's patch for CVE-2026-35312 immediately, prioritizing any internet-facing or externally reachable Oracle Virtual Directory deployments running versions 12.2.1.4.0 or 14.1.2.0.0. The patch was made available as part of Oracle's Critical Patch Update cycle; consult Oracle Support Document and the relevant CPU advisory for the specific patch identifier and installation instructions. Where immediate patching is not feasible, restrict network access to the Virtual Directory Server port to trusted hosts only using perimeter controls or host-based firewall rules. Monitor directory service logs for anomalous bind attempts, unexpected process spawning from the Virtual Directory Server process, and unusual outbound connections originating from the host. Given the unauthenticated nature of the flaw and the critical score, treat this as a patch-now priority regardless of current exploitation status.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →