SYS::ONLINE
Wasteland.
Briefs1413
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60215 2026-07-21

CVE-2026-60215: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker with network access take over affected systems over TCP."

A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker with network access take over affected systems over TCP.

What Is It

CVE-2026-60215 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in full takeover of the product.

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning it is network-reachable, low-complexity, requires no privileges and no user interaction, and delivers high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of remote, unauthenticated exploitation and low attack complexity places this at the top of the severity scale. With no privileges or user interaction required and complete compromise as the outcome, any exposed and unpatched Coherence instance is a high-value target. The impact spans all three security properties; data confidentiality, integrity, and system availability.

What's Vulnerable

Oracle lists the following supported Oracle Coherence versions as affected:

Patch Status

Oracle addressed this vulnerability in its Critical Patch Update of July 2026 (cpujul2026). Organizations running affected versions should apply the fixes from that Critical Patch Update.

Note: The supplied source material does not include a CISA KEV entry for this CVE, so there is no confirmation of active exploitation in the wild at this time.

Sources