SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60236 2026-07-21

CVE-2026-60236: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"A critical, easily exploitable vulnerability in Oracle Coherence lets a remote, unauthenticated attacker fully compromise the product over the network, carrying a maximum-severity CVSS 3.1 score of 9.8."

A critical, easily exploitable vulnerability in Oracle Coherence lets a remote, unauthenticated attacker fully compromise the product over the network, carrying a maximum-severity CVSS 3.1 score of 9.8.

What Is It

CVE-2026-60236 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in complete takeover of the product. The vulnerability scores CVSS 3.1 Base 9.8 (CRITICAL), with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning network-reachable, low complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of network attack vector, no authentication, low attack complexity, and full compromise puts this at the top of the severity scale. An attacker who can reach an affected Coherence instance over TCP can take it over without credentials or victim interaction. Because Coherence is widely deployed as an in-memory data grid within Fusion Middleware environments, exposed instances represent a high-value, low-effort target.

What's Vulnerable

Oracle Coherence (Oracle Corporation), with the following supported versions affected:

Patch Status

Oracle addressed this issue in its July 2026 Critical Patch Update. Administrators should apply the fixes referenced in the Oracle Critical Patch Update Advisory (cpujul2026) to remediate affected Coherence deployments. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the provided source material; the NVD record currently lists a vulnerability status of "Received."

Sources