A critical, network-exploitable vulnerability in Oracle Coherence lets an unauthenticated attacker fully take over the product, scoring 9.8 on the CVSS 3.1 scale.
What Is It
CVE-2026-60234 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access over TCP to compromise Oracle Coherence. Successful exploitation results in complete takeover of the product. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required, with high confidentiality, integrity, and availability impact.
Why It Matters
The combination of an unauthenticated attacker, remote network reach, low attack complexity, and no user interaction makes this an attractive target for exploitation. Because a successful attack yields full takeover of the affected Coherence instance, with high impact across confidentiality, integrity, and availability, any exposed instance represents a serious risk to the data and services it supports. The supplied source material does not include a CISA KEV entry, so there is no confirmation of active exploitation at this time.
What's Vulnerable
The affected product is Oracle Coherence (Oracle Corporation). According to the NVD record, the affected supported versions are:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
The vulnerability was reported by Oracle ([email protected]) and published July 21, 2026, with an NVD status of "Received." Oracle references its July 2026 Critical Patch Update advisory as the source of the fix. Organizations running affected versions should consult the Oracle Critical Patch Update and apply the corresponding updates.
Sources
- Oracle Security Alerts; Critical Patch Update, July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60234: https://nvd.nist.gov/vuln/detail/CVE-2026-60234