A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated network attacker fully compromise and take over the product, scoring a maximum-severity CVSS 9.8.
What Is It
CVE-2026-60227 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's NVD record, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in a complete takeover of the product.
The vulnerability carries a CVSS 3.1 base score of 9.8 (Critical), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That combination, network attack vector, low attack complexity, no privileges, and no user interaction required, means it can be exploited remotely with minimal effort while delivering high impact to confidentiality, integrity, and availability.
Why It Matters
Oracle Coherence is an in-memory data grid widely embedded in enterprise middleware deployments. A flaw that grants full takeover to an unauthenticated remote attacker over TCP removes every meaningful barrier to compromise. The maximum-tier impact across all three security properties (C/I/A rated High) means an attacker who reaches an exposed instance can read, alter, and disrupt the data and services it hosts.
What's Vulnerable
Per the NVD record, the affected supported versions of Oracle Coherence are:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
The vulnerability is published under Oracle's July 2026 Critical Patch Update. Organizations should consult the Oracle Critical Patch Update advisory (cpujul2026) and apply the vendor's fixes for the affected Oracle Coherence versions. No CISA KEV entry confirming active exploitation was present in the supplied source material.
Sources
- Oracle Critical Patch Update Advisory – July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD – CVE-2026-60227: https://nvd.nist.gov/vuln/detail/CVE-2026-60227