SYS::ONLINE
Wasteland.
Briefs1411
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60228 2026-07-21

CVE-2026-60228: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"Oracle disclosed CVE-2026-60228, a critical (CVSS 9.8) remotely exploitable vulnerability in Oracle Coherence that lets an unauthenticated attacker fully take over affected systems."

Oracle disclosed CVE-2026-60228, a critical (CVSS 9.8) remotely exploitable vulnerability in Oracle Coherence that lets an unauthenticated attacker fully take over affected systems.

What Is It

CVE-2026-60228 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful exploitation results in complete takeover of the product. It carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of network-based, unauthenticated access and low attack complexity means an attacker needs no credentials and no victim interaction to reach the vulnerable component. Because successful attacks lead to full takeover of Oracle Coherence, an exploited instance can expose sensitive data, allow tampering, and be knocked offline; the maximum impact across all three CVSS dimensions. This profile makes it a high-priority patching target for any organization running affected middleware exposed to reachable networks.

What's Vulnerable

Oracle Coherence (vendor: Oracle Corporation), Core component of Oracle Fusion Middleware. The affected supported versions are:

Patch Status

The vulnerability was addressed in Oracle's Critical Patch Update of July 2026. Organizations should apply the fixes documented in the July 2026 CPU advisory to remediate affected Oracle Coherence versions. The NVD record currently lists a vulnerability status of "Received," reflecting recent publication. No CISA KEV entry was supplied with this material, so active exploitation is not confirmed in the source data.

Sources