SYS::ONLINE
Wasteland.
Briefs1406
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60229 2026-07-21

CVE-2026-60229: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"Oracle has disclosed CVE-2026-60229, a critical (CVSS 9.8) vulnerability in Oracle Coherence that lets an unauthenticated attacker with network access fully compromise the product over TCP."

Oracle has disclosed CVE-2026-60229, a critical (CVSS 9.8) vulnerability in Oracle Coherence that lets an unauthenticated attacker with network access fully compromise the product over TCP.

What Is It

CVE-2026-60229 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in complete takeover of the product. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of network attack vector, low attack complexity, no required privileges, and no user interaction makes this flaw trivial to exploit remotely. Because a successful attack results in full takeover of Oracle Coherence, an attacker can gain complete control over affected systems; compromising data, altering it, and disrupting availability. Oracle Coherence is commonly deployed as an in-memory data grid within enterprise middleware stacks, making exposed instances high-value targets.

What's Vulnerable

The following supported versions of Oracle Coherence (Oracle Fusion Middleware) are affected:

Patch Status

Oracle addressed this vulnerability in its Critical Patch Update for July 2026 (CPU July 2026). Administrators should apply the fixes referenced in Oracle's July 2026 Critical Patch Update advisory as soon as possible. As of this writing, the NVD record is in "Received" status, and there is no CISA KEV entry confirming active exploitation.

Sources