Summary
CVE-2026-35300 is a critical severity vulnerability residing in the Core component of Oracle WebLogic Server, assigned a CVSS v3.1 base score of 9.8. The flaw is exploitable by unauthenticated remote attackers over the network with no user interaction required, resulting in full compromise of confidentiality, integrity, and availability of the targeted system. Oracle has released patches addressing this issue as part of the June 2026 Critical Patch Update.
Technical details
- Affected component: Oracle WebLogic Server Core component
- Trigger conditions: No authentication or user interaction is required; any network-reachable WebLogic instance is a viable target
- Attack vector: Remote, unauthenticated exploitation over TCP — targeting standard WebLogic listener ports (HTTP/HTTPS 7001/7002, T3, IIOP)
- Impact: Full compromise of confidentiality, integrity, and availability, consistent with unauthenticated remote code execution on the underlying server
Affected software
- Oracle WebLogic Server 12.2.1.4.0
- Oracle WebLogic Server 14.1.1.0.0
- Oracle WebLogic Server 14.1.2.0.0
- Oracle WebLogic Server 15.1.1.0.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Patch Update for June 2026. Patch installation instructions are available via the Oracle CPU June 2026 Patch Availability Document (My Oracle Support Note CPU195), accessible through My Oracle Support.
- If immediate patching is not feasible: Restrict network access to WebLogic application and administrative ports (TCP 7001, 7002, T3, IIOP) to explicitly trusted IP ranges. Remove or block any direct public internet exposure of WebLogic instances until the patch is applied.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

