SYS::ONLINE
Wasteland.
Briefs1411
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60225 2026-07-21

CVE-2026-60225: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker take over the product over the network via HTTP, disclosed in Oracle's July 2026 Critical Patch Update."

A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker take over the product over the network via HTTP, disclosed in Oracle's July 2026 Critical Patch Update.

What Is It

CVE-2026-60225 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. A successful attack can result in complete takeover of the product.

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of no authentication, network reachability over HTTP, low attack complexity, and full compromise of the confidentiality, integrity, and availability triad places this among the most severe classes of vulnerabilities. Oracle explicitly characterizes it as easily exploitable and capable of full takeover, meaning an exposed and unpatched instance offers an attacker a direct path to control the affected service.

What's Vulnerable

The following supported versions of Oracle Coherence are affected:

The vulnerable component is identified as Core.

Patch Status

Oracle addressed CVE-2026-60225 in its July 2026 Critical Patch Update (cpujul2026). Administrators should consult the Oracle Critical Patch Update advisory and apply the corresponding fixes for their Oracle Coherence versions. No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the provided source material.

Sources