A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker take over the product over the network via HTTP, disclosed in Oracle's July 2026 Critical Patch Update.
What Is It
CVE-2026-60225 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. A successful attack can result in complete takeover of the product.
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of no authentication, network reachability over HTTP, low attack complexity, and full compromise of the confidentiality, integrity, and availability triad places this among the most severe classes of vulnerabilities. Oracle explicitly characterizes it as easily exploitable and capable of full takeover, meaning an exposed and unpatched instance offers an attacker a direct path to control the affected service.
What's Vulnerable
The following supported versions of Oracle Coherence are affected:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
The vulnerable component is identified as Core.
Patch Status
Oracle addressed CVE-2026-60225 in its July 2026 Critical Patch Update (cpujul2026). Administrators should consult the Oracle Critical Patch Update advisory and apply the corresponding fixes for their Oracle Coherence versions. No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the provided source material.
Sources
- Oracle Critical Patch Update Advisory; July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60225: https://nvd.nist.gov/vuln/detail/CVE-2026-60225