SYS::ONLINE
Wasteland.
Briefs1411
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60227 2026-07-21

Oracle Coherence Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60227)

"A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated network attacker fully compromise and take over the product, scoring a maximum-severity CVSS 9.8."

A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated network attacker fully compromise and take over the product, scoring a maximum-severity CVSS 9.8.

What Is It

CVE-2026-60227 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's NVD record, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in a complete takeover of the product.

The vulnerability carries a CVSS 3.1 base score of 9.8 (Critical), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That combination, network attack vector, low attack complexity, no privileges, and no user interaction required, means it can be exploited remotely with minimal effort while delivering high impact to confidentiality, integrity, and availability.

Why It Matters

Oracle Coherence is an in-memory data grid widely embedded in enterprise middleware deployments. A flaw that grants full takeover to an unauthenticated remote attacker over TCP removes every meaningful barrier to compromise. The maximum-tier impact across all three security properties (C/I/A rated High) means an attacker who reaches an exposed instance can read, alter, and disrupt the data and services it hosts.

What's Vulnerable

Per the NVD record, the affected supported versions of Oracle Coherence are:

Patch Status

The vulnerability is published under Oracle's July 2026 Critical Patch Update. Organizations should consult the Oracle Critical Patch Update advisory (cpujul2026) and apply the vendor's fixes for the affected Oracle Coherence versions. No CISA KEV entry confirming active exploitation was present in the supplied source material.

Sources