SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60234 2026-07-21

Oracle Coherence Core Flaw (CVE-2026-60234): Unauthenticated Takeover, CVSS 9.8

"A critical, network-exploitable vulnerability in Oracle Coherence lets an unauthenticated attacker fully take over the product, scoring 9.8 on the CVSS 3.1 scale."

A critical, network-exploitable vulnerability in Oracle Coherence lets an unauthenticated attacker fully take over the product, scoring 9.8 on the CVSS 3.1 scale.

What Is It

CVE-2026-60234 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access over TCP to compromise Oracle Coherence. Successful exploitation results in complete takeover of the product. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required, with high confidentiality, integrity, and availability impact.

Why It Matters

The combination of an unauthenticated attacker, remote network reach, low attack complexity, and no user interaction makes this an attractive target for exploitation. Because a successful attack yields full takeover of the affected Coherence instance, with high impact across confidentiality, integrity, and availability, any exposed instance represents a serious risk to the data and services it supports. The supplied source material does not include a CISA KEV entry, so there is no confirmation of active exploitation at this time.

What's Vulnerable

The affected product is Oracle Coherence (Oracle Corporation). According to the NVD record, the affected supported versions are:

Patch Status

The vulnerability was reported by Oracle ([email protected]) and published July 21, 2026, with an NVD status of "Received." Oracle references its July 2026 Critical Patch Update advisory as the source of the fix. Organizations running affected versions should consult the Oracle Critical Patch Update and apply the corresponding updates.

Sources