SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60250 2026-07-21

CVE-2026-60250: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated, network-based attacker fully take over the product, and Oracle addressed it in the July 2026 Critical Patch Update."

A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated, network-based attacker fully take over the product, and Oracle addressed it in the July 2026 Critical Patch Update.

What Is It

CVE-2026-60250 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in complete takeover of the product.

The vulnerability carries a CVSS 3.1 Base Score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating high impact to confidentiality, integrity, and availability across a network attack path requiring no privileges and no user interaction.

Why It Matters

Because the vulnerability requires no authentication, no user interaction, and only network access over TCP, the barrier to exploitation is minimal. The maximum-tier impact across all three security properties, confidentiality, integrity, and availability, combined with the potential for full product takeover makes this one of the most serious classes of flaw. Any exposed, unpatched Coherence instance is a high-value target for attackers.

What's Vulnerable

The affected product is Oracle Coherence (Oracle Fusion Middleware). The supported versions listed as affected are:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (CPU). Organizations running any affected version should apply the fixes referenced in the Oracle Critical Patch Update Advisory as soon as possible. No CISA KEV entry confirming active exploitation was supplied for this CVE at the time of writing.

Sources