SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60253 2026-07-21

CVE-2026-60253: Critical Unauthenticated Takeover in Oracle Coherence

"Oracle's July 2026 Critical Patch Update discloses CVE-2026-60253, a CVSS 9.8 flaw that lets an unauthenticated attacker fully compromise Oracle Coherence over the network."

Oracle's July 2026 Critical Patch Update discloses CVE-2026-60253, a CVSS 9.8 flaw that lets an unauthenticated attacker fully compromise Oracle Coherence over the network.

What Is It

CVE-2026-60253 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in a complete takeover of the product.

The CVSS 3.1 vector, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflects a network-reachable attack requiring low complexity, no privileges, and no user interaction, with high impact to confidentiality, integrity, and availability.

Why It Matters

With a base score of 9.8 (CRITICAL), this is among the most severe categories of vulnerability. The combination of no authentication, low attack complexity, and full takeover means an exposed Coherence instance can be seized outright by a remote attacker. The exploitability sub-score is a maximum 3.9, underscoring how little effort an attack requires.

Note: no CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed by KEV at this time.

What's Vulnerable

Per the NVD record, the affected supported versions of Oracle Coherence (Oracle Corporation) are:

The vulnerability resides in the Core component of the product.

Patch Status

The vulnerability is addressed in Oracle's July 2026 Critical Patch Update (cpujul2026). Administrators should apply the fixes referenced in the Oracle Critical Patch Update advisory for the affected Coherence versions. Given the unauthenticated, network-based nature of the flaw, patching should be treated as urgent.

Sources