SYS::ONLINE
Wasteland.
Briefs1402
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60197 2026-07-21

Oracle Coherence Core Flaw (CVE-2026-60197): Unauthenticated Takeover, CVSS 9.8

"A critical, network-exploitable vulnerability in Oracle Coherence lets an unauthenticated attacker fully compromise the product, earning a CVSS 3.1 base score of 9.8."

A critical, network-exploitable vulnerability in Oracle Coherence lets an unauthenticated attacker fully compromise the product, earning a CVSS 3.1 base score of 9.8.

What Is It

CVE-2026-60197 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful exploitation can result in complete takeover of Oracle Coherence.

The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low attack complexity, no privileges required, and no user interaction, with high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of no authentication, low complexity, and remote reachability over TCP places this at the top of the severity scale (9.8 CRITICAL, exploitability sub-score 3.9). An attacker who can reach an affected Coherence instance over the network can take it over outright, with full impact across confidentiality, integrity, and availability. There is no confirmed active-exploitation (KEV) data in the supplied source material.

What's Vulnerable

The affected product is Oracle Coherence (Oracle Corporation), within Oracle Fusion Middleware. The supported versions listed as affected are:

Patch Status

The vulnerability was published on 2026-07-21 with an NVD status of "Received." It is addressed in Oracle's July 2026 Critical Patch Update. Administrators running any of the affected versions should apply the fixes referenced in the Oracle Critical Patch Update Advisory. No separate CISA KEV required-action data is present in the supplied source material.

Sources