SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60248 2026-07-21

CVE-2026-60248: Critical Oracle Coherence Takeover Flaw in Fusion Middleware

"A critical vulnerability in Oracle Coherence (CVSS 9.3) lets an attacker fully take over the product and pivot into additional connected systems, patched in Oracle's July 2026 Critical Patch Update."

A critical vulnerability in Oracle Coherence (CVSS 9.3) lets an attacker fully take over the product and pivot into additional connected systems, patched in Oracle's July 2026 Critical Patch Update.

What Is It

CVE-2026-60248 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Oracle rates it CVSS 3.1 base score 9.3 (Critical). The flaw is described as easily exploitable, allowing an unauthenticated attacker with logon access to the infrastructure where Oracle Coherence runs to compromise the product. Successful exploitation can result in a complete takeover of Oracle Coherence.

Why It Matters

The CVSS vector (AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) reflects high impact to confidentiality, integrity, and availability. Critically, the vulnerability carries a scope change: while the flaw resides in Oracle Coherence, attacks may significantly impact additional products beyond Coherence itself. This lateral impact, combined with low attack complexity and no privileges or user interaction required, makes it a serious risk for any environment running an affected version.

What's Vulnerable

The following supported Oracle Coherence versions are affected:

The attack vector is local, requiring the attacker to have logon access to the infrastructure hosting Oracle Coherence.

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (CPU). Organizations running affected versions should consult the Oracle Critical Patch Update advisory and apply the provided fixes. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed by KEV in the available source material.

Sources