SYS::ONLINE
Wasteland.
Briefs1408
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60217 2026-07-21

CVE-2026-60217: Critical Unauthenticated Takeover in Oracle Coherence

"Oracle has disclosed CVE-2026-60217, a maximum-severity (CVSS 10.0) flaw in Oracle Coherence that lets an unauthenticated, network-based attacker fully compromise the product."

Oracle has disclosed CVE-2026-60217, a maximum-severity (CVSS 10.0) flaw in Oracle Coherence that lets an unauthenticated, network-based attacker fully compromise the product.

What Is It

CVE-2026-60217 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks can result in complete takeover of Oracle Coherence. The issue carries a CVSS 3.1 base score of 10.0 (CRITICAL) with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.

Why It Matters

The maximum score reflects the worst-case combination: no authentication or user interaction is required, attack complexity is low, and the impact spans confidentiality, integrity, and availability at the "High" level. Critically, the scope is changed, while the vulnerability resides in Oracle Coherence, Oracle notes that attacks may significantly impact additional products beyond Coherence itself. That lateral reach, combined with unauthenticated network exploitability, makes this a high-priority remediation target for any environment running affected versions.

What's Vulnerable

Oracle Coherence is affected across the following supported versions:

The vulnerability is reachable over the network via TCP.

Patch Status

The fix is addressed in Oracle's July 2026 Critical Patch Update. Administrators should consult the Oracle Critical Patch Update advisory (cpujul2026) and apply the relevant fixes for their Coherence version. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the provided source material.

Sources