A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated, network-based attacker fully compromise and take over affected deployments.
What Is It
CVE-2026-60212 is a vulnerability in the Core component of the Oracle Coherence product, part of Oracle Fusion Middleware. Per Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful exploitation can result in a complete takeover of Oracle Coherence. The issue carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Why It Matters
The scoring reflects the worst-case profile for a network service: attack vector is Network, attack complexity is Low, and neither privileges nor user interaction are required. Confidentiality, integrity, and availability impacts are all High, meaning a successful attack grants full control over the affected instance. Because exploitation requires no authentication, any Coherence node reachable over TCP is directly at risk.
What's Vulnerable
The following supported versions of Oracle Coherence (vendor: Oracle Corporation) are affected:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
The vulnerability was published on 2026-07-21 with NVD status "Received." Oracle addresses this issue in its July 2026 Critical Patch Update; administrators should consult that advisory and apply the associated fixes for their affected version. No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the provided source material.