A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated, network-based attacker fully compromise the product, addressed in Oracle's July 2026 Critical Patch Update.
What Is It
CVE-2026-60216 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in complete takeover of Oracle Coherence.
The CVSS 3.1 base score is 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting network attack vector, low attack complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of no authentication, network reachability over TCP, low attack complexity, and full takeover makes this an attractive target. With high impact across all three security dimensions and an exploitability sub-score of 3.9 (the maximum), any exposed and unpatched Coherence instance is at serious risk of complete compromise.
What's Vulnerable
Oracle Coherence (Oracle Fusion Middleware, Core component). The affected supported versions are:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Administrators running any of the affected versions should apply the fixes from that Critical Patch Update. No CISA KEV entry was supplied, so active exploitation is not confirmed in the available source material.
Sources
- Oracle Critical Patch Update Advisory, July 2026, https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60216, https://nvd.nist.gov/vuln/detail/CVE-2026-60216