SYS::ONLINE
Wasteland.
Briefs1408
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60221 2026-07-21

CVE-2026-60221: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"A critical vulnerability (CVSS 9.8) in Oracle Coherence lets an unauthenticated network attacker fully compromise the product, addressed in Oracle's July 2026 Critical Patch Update."

A critical vulnerability (CVSS 9.8) in Oracle Coherence lets an unauthenticated network attacker fully compromise the product, addressed in Oracle's July 2026 Critical Patch Update.

What Is It

CVE-2026-60221 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful exploitation can result in complete takeover of the product.

It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting network attack vector, low attack complexity, no required privileges, no user interaction, and high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of unauthenticated network access, low attack complexity, and full compromise makes this an especially dangerous flaw. An attacker needs no credentials and no user interaction to take over an affected Coherence instance. The maximum impact across all three security properties, confidentiality, integrity, and availability, means a successful attack can read, alter, and disrupt the targeted system.

What's Vulnerable

The vulnerability affects the Oracle Coherence product (Core component) of Oracle Fusion Middleware. Per Oracle, the affected supported versions are:

Patch Status

Oracle addressed this vulnerability in its Critical Patch Update published July 21, 2026. Organizations running affected Coherence versions should apply the fixes referenced in the Oracle Critical Patch Update Advisory for July 2026. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed by the provided source material.

Sources