SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60249 2026-07-21

CVE-2026-60249: Critical Takeover Flaw in Oracle Coherence

"A critical (CVSS 9.0) vulnerability in Oracle Coherence lets a low-privileged, adjacent-network attacker fully take over the product and impact other systems, disclosed in Oracle's July 2026 Critical Patch Update."

A critical (CVSS 9.0) vulnerability in Oracle Coherence lets a low-privileged, adjacent-network attacker fully take over the product and impact other systems, disclosed in Oracle's July 2026 Critical Patch Update.

What Is It

CVE-2026-60249 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle, it is an easily exploitable flaw that allows a low-privileged attacker with access to the physical communication segment attached to the hardware where Oracle Coherence runs to compromise the product. Successful attacks can result in complete takeover of Oracle Coherence. Because the vulnerability carries a scope change, attacks may significantly impact additional products beyond Coherence itself.

Why It Matters

The flaw carries a CVSS 3.1 base score of 9.0 (CRITICAL), with high impact to confidentiality, integrity, and availability. Its vector, CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, reflects low attack complexity, no user interaction, and a changed scope, meaning a successful compromise can reach beyond the vulnerable component. While exploitation requires adjacent-network access and low privileges, the potential for full product takeover and lateral impact makes this a high-priority fix for affected environments.

What's Vulnerable

The following supported versions of Oracle Coherence are affected:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Administrators of affected Oracle Coherence deployments should apply the fixes provided in that update. This CVE record was published on 2026-07-21 with a status of "Received," and no CISA KEV entry was supplied, so there is no confirmation of active exploitation in the provided source material.

Sources