SYS::ONLINE
Wasteland.
Briefs1411
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60220 2026-07-21

CVE-2026-60220: Critical Oracle Coherence Flaw Allows Unauthenticated Remote Compromise

"A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated network attacker compromise the product and pivot into other systems, carrying a CVSS 3.1 base score of 9.3."

A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated network attacker compromise the product and pivot into other systems, carrying a CVSS 3.1 base score of 9.3.

What Is It

CVE-2026-60220 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, an unauthenticated attacker with network access via TCP can exploit the flaw to compromise Oracle Coherence. The attack complexity is low, but successful exploitation requires human interaction from a person other than the attacker. Notably, the vulnerability has a scope change (CVSS S:C), meaning that although the flaw resides in Oracle Coherence, attacks may significantly impact additional products beyond it.

Why It Matters

The vulnerability carries a CVSS 3.1 base score of 9.3 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, up to all Oracle Coherence accessible data, as well as unauthorized read access to critical or all Oracle Coherence accessible data. In short, both confidentiality and integrity impacts are High. The combination of no required privileges, network reachability, low complexity, and cross-product scope change makes this a high-priority concern for any environment running affected versions.

What's Vulnerable

The affected product is Oracle Coherence (vendor: Oracle Corporation), Core component. The supported versions listed as affected are:

Patch Status

Oracle addressed this vulnerability as part of its July 2026 Critical Patch Update. Organizations running affected versions should apply the fixes referenced in the Oracle Critical Patch Update Advisory (July 2026). No CISA KEV entry was supplied with this record, so there is no confirmation of active exploitation in the provided source material.

Sources