SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60241 2026-07-21

Oracle Coherence Core Flaw (CVE-2026-60241): Unauthenticated Takeover, CVSS 9.8

"A critical, network-exploitable vulnerability in Oracle Coherence lets an unauthenticated attacker fully compromise the product over HTTP, scoring 9.8 on the CVSS scale."

A critical, network-exploitable vulnerability in Oracle Coherence lets an unauthenticated attacker fully compromise the product over HTTP, scoring 9.8 on the CVSS scale.

What Is It

CVE-2026-60241 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful exploitation can result in complete takeover of the product. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning no privileges, no user interaction, and high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of network attack vector, low attack complexity, and no required authentication or user interaction makes this among the most dangerous vulnerability classes. An attacker only needs HTTP reachability to the affected service to achieve full takeover, exposing hosted data and the integrity and availability of the system. The maximum impact ratings across all three CIA pillars underscore that a compromise is not partial; it is total control of the affected Coherence instance.

What's Vulnerable

The affected product is Oracle Coherence (vendor: Oracle Corporation). Oracle lists the following supported versions as affected:

Patch Status

Oracle addresses this issue in its July 2026 Critical Patch Update. Organizations running affected versions should consult the Oracle Critical Patch Update advisory and apply the corresponding fixes. No CISA KEV entry accompanies this record, so active exploitation is not confirmed in the supplied source material; given the 9.8 severity and unauthenticated remote nature, prompt patching is nonetheless warranted.

Sources