SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60247 2026-07-21

CVE-2026-60247: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"A critical, network-exploitable vulnerability in Oracle Coherence lets an unauthenticated attacker fully compromise the product over HTTP, carrying a CVSS 3.1 base score of 9.8."

A critical, network-exploitable vulnerability in Oracle Coherence lets an unauthenticated attacker fully compromise the product over HTTP, carrying a CVSS 3.1 base score of 9.8.

What Is It

CVE-2026-60247 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks can result in complete takeover of the product. It is rated CVSS 3.1 base score 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required.

Why It Matters

The vulnerability delivers high impact across confidentiality, integrity, and availability. Because exploitation requires no authentication, no user interaction, and only network access over HTTP, the barrier to attack is low and the potential blast radius is a full product takeover. The 9.8 score reflects the maximum exploitability sub-score (3.9), underscoring how readily an exposed instance could be attacked. Oracle Coherence is commonly used as an in-memory data grid within enterprise middleware stacks, making compromise consequential for the applications and data it supports.

What's Vulnerable

The affected product is Oracle Coherence (Oracle Corporation), component Core. The supported versions listed as affected are:

Patch Status

No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the provided source material. The NVD record status is "Received," published 2026-07-21. Remediation guidance is available through Oracle's July 2026 Critical Patch Update advisory; administrators should consult that advisory and apply the corresponding fixes for the affected Oracle Coherence versions.

Sources