Oracle's July 2026 Critical Patch Update discloses CVE-2026-60210, a critical (CVSS 9.8) flaw allowing an unauthenticated network attacker to fully compromise Oracle Coherence.
What Is It
CVE-2026-60210 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful exploitation results in a complete takeover of the product. The CVSS 3.1 base score is 9.8 (CRITICAL), with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required.
Why It Matters
This vulnerability combines the worst attributes for defenders: it is remotely reachable, requires no authentication, and yields high impact across confidentiality, integrity, and availability. With an attack complexity rated low and no user interaction needed, exploitation is straightforward for an attacker who can reach an exposed Coherence instance over TCP. A full product takeover means an attacker can read, alter, and disrupt the data and services that depend on the cluster.
What's Vulnerable
The affected product is Oracle Coherence (vendor: Oracle Corporation), specifically the Core component. Oracle lists the following supported versions as affected:
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
The vulnerability was published on 2026-07-21 and is addressed in Oracle's July 2026 Critical Patch Update. Organizations running any affected version should apply the fixes referenced in the Oracle Critical Patch Update Advisory. Note: this CVE is not present in the CISA Known Exploited Vulnerabilities catalog based on the supplied data, so there is no confirmation of active exploitation at this time. Given the 9.8 severity and unauthenticated network reachability, prioritize patching.
Sources
- Oracle Critical Patch Update Advisory; July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60210: https://nvd.nist.gov/vuln/detail/CVE-2026-60210