A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated network attacker fully compromise the product, earning a maximum-tier CVSS 3.1 base score of 9.8.
What Is It
CVE-2026-60251 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful exploitation can result in complete takeover of the affected Oracle Coherence instance.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That combination, network attack vector, low attack complexity, no privileges, and no user interaction required, means an attacker can reach and exploit the flaw remotely with minimal effort. The impact is total: high confidentiality, integrity, and availability loss, reflecting full takeover of the product. Oracle Coherence is widely deployed as an in-memory data grid underpinning enterprise middleware, so a compromise can expose sensitive application data and disrupt critical services.
What's Vulnerable
The affected product is Oracle Coherence (Oracle Corporation), Core component. The supported versions listed as affected are:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
This CVE was published as part of Oracle's Critical Patch Update for July 2026. Organizations running any affected version should consult Oracle's July 2026 CPU advisory and apply the corresponding fixes. No CISA KEV entry accompanies this record, so active exploitation is not confirmed in the supplied source material; given the 9.8 severity and unauthenticated remote attack profile, patching should still be prioritized.
Sources
- Oracle Critical Patch Update Advisory, July 2026, https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60251, https://nvd.nist.gov/vuln/detail/CVE-2026-60251