Oracle disclosed a critical (CVSS 9.8) vulnerability in Oracle Coherence that lets an unauthenticated, network-based attacker fully take over affected deployments.
What Is It
CVE-2026-60246 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack results in complete takeover of the product, with high impact to confidentiality, integrity, and availability.
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low attack complexity, no privileges required, and no user interaction.
Why It Matters
The combination of remote reachability, no authentication, and low complexity makes this an attractive target. Because a successful attack yields full takeover with high confidentiality, integrity, and availability impact, an attacker who reaches an exposed Coherence instance over TCP can compromise the data and processing it handles. Oracle rates the exploit as "easily exploitable," raising the urgency for internet-facing or broadly network-accessible deployments.
Note: the supplied CISA KEV entry is empty, so active exploitation is not confirmed in this source material.
What's Vulnerable
The following supported Oracle Coherence versions are listed as affected:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
The affected vendor is Oracle Corporation; the affected component is Core.
Patch Status
The vulnerability was published on 2026-07-21 with an NVD status of "Received." Oracle addresses it in the July 2026 Critical Patch Update. Administrators should consult the Oracle Critical Patch Update advisory and apply the corresponding fixes for their Coherence version. No specific remediation instructions beyond the CPU advisory are present in the supplied data.
Sources
- Oracle Critical Patch Update Advisory, July 2026, https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60246, https://nvd.nist.gov/vuln/detail/CVE-2026-60246