A critical, network-exploitable vulnerability in Oracle Coherence lets an unauthenticated attacker fully compromise the product over TCP.
What Is It
CVE-2026-60240 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in complete takeover of Oracle Coherence. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, no privileges, no user interaction, and high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of network attack vector, low attack complexity, and no required authentication or user interaction makes this among the most serious classes of vulnerability. Because a successful attack results in full takeover, an attacker who can reach an exposed Coherence instance could gain complete control over it. The maximum-rated impact across all three security properties (C/I/A) means data exposure, data manipulation, and service disruption are all in scope.
What's Vulnerable
The affected product is Oracle Coherence (vendor: Oracle Corporation). According to the NVD record, the affected supported versions are:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
Oracle addressed this issue in its July 2026 Critical Patch Update. Organizations running any of the affected Coherence versions should consult and apply the fixes referenced in Oracle's Critical Patch Update advisory (cpujul2026). No CISA KEV entry was supplied with this record, so active exploitation is not confirmed by KEV in the available source material.
Sources
- Oracle Critical Patch Update Advisory – July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60240, https://nvd.nist.gov/vuln/detail/CVE-2026-60240