SYS::ONLINE
Wasteland.
Briefs1413
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60226 2026-07-21

CVE-2026-60226: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"Oracle disclosed a critical (CVSS 9.8) vulnerability in Oracle Coherence that lets an unauthenticated network attacker fully compromise affected systems, patched in the July 2026 Critical Patch Update."

Oracle disclosed a critical (CVSS 9.8) vulnerability in Oracle Coherence that lets an unauthenticated network attacker fully compromise affected systems, patched in the July 2026 Critical Patch Update.

What Is It

CVE-2026-60226 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, it is an "easily exploitable" flaw that allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful exploitation can result in complete takeover of the product. It carries a CVSS 3.1 base score of 9.8 (CRITICAL), with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning no privileges, no user interaction, and low attack complexity, with high confidentiality, integrity, and availability impact.

Why It Matters

The combination of network reachability, no authentication requirement, and low complexity makes this an attractive target. A successful attack yields full takeover of Oracle Coherence, an in-memory data grid frequently used in high-value enterprise middleware deployments. The 9.8 score reflects the worst-case triad: an attacker can read data, alter it, and disrupt availability. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed at the time of writing; however, the low barrier to exploitation warrants urgent attention regardless.

What's Vulnerable

Per the NVD record, the affected supported versions of Oracle Coherence (vendor: Oracle Corporation) are:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (CPU). Administrators should apply the fixes referenced in Oracle's security alert for CPU July 2026. Given the critical severity and unauthenticated network exploitability, patching affected Coherence versions should be prioritized.

Sources