SYS::ONLINE
Wasteland.
Briefs1411
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60219 2026-07-21

CVE-2026-60219: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker with network access take full control of the product over TCP."

A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker with network access take full control of the product over TCP.

What Is It

CVE-2026-60219 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful exploitation can result in complete takeover of the product.

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low attack complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of an unauthenticated network-reachable attack path, low complexity, and a full-takeover outcome places this among the most severe classes of vulnerability. No credentials or user interaction are needed, so any exposed, unpatched Coherence instance is directly at risk. Oracle Coherence is commonly deployed as an in-memory data grid underpinning enterprise Fusion Middleware applications, meaning a compromise can affect the confidentiality, integrity, and availability of dependent systems.

What's Vulnerable

Per the NVD record and Oracle, the affected supported versions of Oracle Coherence are:

The affected component is Core, within Oracle Fusion Middleware.

Patch Status

The vulnerability was published on 2026-07-21 and is addressed in Oracle's July 2026 Critical Patch Update. Administrators should apply the fixes referenced in the Oracle Critical Patch Update advisory (cpujul2026) without delay, prioritizing internet-exposed instances. This CVE does not appear in a supplied CISA KEV entry, so there is no confirmation of active exploitation in the provided source material.

Sources