SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60239 2026-07-21

CVE-2026-60239: Critical Oracle Coherence Flaw Enables Low-Privilege Data Compromise

"Oracle's July 2026 Critical Patch Update discloses CVE-2026-60239, a critical (CVSS 9.6) vulnerability in Oracle Coherence that lets a low-privileged network attacker compromise the product and impact data far beyond it."

Oracle's July 2026 Critical Patch Update discloses CVE-2026-60239, a critical (CVSS 9.6) vulnerability in Oracle Coherence that lets a low-privileged network attacker compromise the product and impact data far beyond it.

What Is It

CVE-2026-60239 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, it is an "easily exploitable" flaw that allows a low-privileged attacker with network access via HTTP to compromise Oracle Coherence. It carries a CVSS 3.1 base score of 9.6 (CRITICAL) with vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N, network attack vector, low complexity, low privileges required, and no user interaction.

Why It Matters

The vector's scope change (S:C) is the key detail: while the vulnerability resides in Oracle Coherence, successful attacks "may significantly impact additional products," extending damage beyond the vulnerable component itself. Impact is high for both confidentiality and integrity; attackers can gain unauthorized read access to all Coherence-accessible data, and can create, delete, or modify critical data. There is no availability impact (A:N). The combination of low attack complexity and only low privileges required makes this a realistic target for lateral movement and data compromise in affected environments.

What's Vulnerable

The affected product is Oracle Coherence (Oracle Fusion Middleware). Oracle lists the following supported versions as affected:

Patch Status

A fix is available via Oracle's July 2026 Critical Patch Update (cpujul2026). Administrators running any affected Coherence version should apply the corresponding CPU patch. Note: there is no CISA KEV entry in the supplied data, so active exploitation is not confirmed at this time.

Sources