SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60244 2026-07-21

CVE-2026-60244: Critical Unauthenticated Takeover in Oracle Coherence

"A critical, easily exploitable flaw in Oracle Coherence lets an unauthenticated attacker with network access fully compromise the product, earning a CVSS 3.1 base score of 9.8."

A critical, easily exploitable flaw in Oracle Coherence lets an unauthenticated attacker with network access fully compromise the product, earning a CVSS 3.1 base score of 9.8.

What Is It

CVE-2026-60244 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. A successful attack can result in complete takeover of Oracle Coherence.

Why It Matters

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL). Its vector, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflects the worst-case exploitation profile: network attack vector, low attack complexity, no privileges required, and no user interaction, combined with high impact to confidentiality, integrity, and availability. Because exploitation requires no authentication and can be carried out remotely over HTTP, any exposed instance is at significant risk of full compromise.

What's Vulnerable

The affected product is Oracle Coherence (vendor: Oracle Corporation), within Oracle Fusion Middleware. The supported versions listed as affected are:

Patch Status

Oracle addressed this issue in its July 2026 Critical Patch Update. Administrators should consult the Oracle Critical Patch Update advisory and apply the relevant fixes for the affected Oracle Coherence versions. No CISA KEV entry accompanied this record, so there is no confirmation of active exploitation in the supplied source material.

Sources