A critical vulnerability (CVSS 9.8) in Oracle Coherence lets an unauthenticated network attacker fully compromise the product, addressed in Oracle's July 2026 Critical Patch Update.
What Is It
CVE-2026-60221 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful exploitation can result in complete takeover of the product.
It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting network attack vector, low attack complexity, no required privileges, no user interaction, and high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of unauthenticated network access, low attack complexity, and full compromise makes this an especially dangerous flaw. An attacker needs no credentials and no user interaction to take over an affected Coherence instance. The maximum impact across all three security properties, confidentiality, integrity, and availability, means a successful attack can read, alter, and disrupt the targeted system.
What's Vulnerable
The vulnerability affects the Oracle Coherence product (Core component) of Oracle Fusion Middleware. Per Oracle, the affected supported versions are:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
Oracle addressed this vulnerability in its Critical Patch Update published July 21, 2026. Organizations running affected Coherence versions should apply the fixes referenced in the Oracle Critical Patch Update Advisory for July 2026. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed by the provided source material.