SYS::ONLINE
Wasteland.
Briefs1404
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60209 2026-07-21

CVE-2026-60209: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"A critical vulnerability in Oracle Coherence lets unauthenticated attackers with network access fully compromise the product, carrying a maximum-severity CVSS score of 9.8."

A critical vulnerability in Oracle Coherence lets unauthenticated attackers with network access fully compromise the product, carrying a maximum-severity CVSS score of 9.8.

What Is It

CVE-2026-60209 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful exploitation can result in complete takeover of Oracle Coherence.

It is rated CVSS 3.1 Base Score 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting network attack vector, low attack complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.

Why It Matters

This vulnerability combines the worst-case attributes for defenders: it is remotely reachable over the network, requires no authentication, no user interaction, and is described by the vendor as "easily exploitable." A successful attack results in full takeover of the affected Oracle Coherence instance, compromising confidentiality, integrity, and availability alike. The 9.8 base score places it at the top of the severity scale.

What's Vulnerable

The affected product is Oracle Coherence (component: Core), from Oracle Corporation. The supported versions listed as affected are:

Patch Status

The vulnerability was published on 2026-07-21 and is addressed in Oracle's Critical Patch Update advisory for July 2026. Organizations running affected versions should consult the Oracle CPU advisory and apply the associated fixes. No CISA KEV entry was supplied with this record, so active exploitation is not confirmed by KEV at this time.

Sources