A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated network attacker fully compromise the product, carrying a CVSS 3.1 base score of 9.8.
What Is It
CVE-2026-60254 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in complete takeover of the affected Oracle Coherence instance.
Why It Matters
The vulnerability is rated CVSS 3.1 base score 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That combination, network attack vector, low attack complexity, no privileges required, and no user interaction, means an attacker can reach and exploit it remotely with minimal effort. The impact is maximal across all three dimensions: high confidentiality, high integrity, and high availability impact. Full takeover of a Coherence data-grid node exposes the data it holds and the systems that depend on it.
Note: no CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed by KEV at this time.
What's Vulnerable
The affected product is Oracle Coherence (vendor: Oracle Corporation). Per the NVD record, the supported versions affected are:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
The vulnerability was disclosed by Oracle (source identifier [email protected]) and published on 2026-07-21 as part of Oracle's Critical Patch Update. Remediation guidance is provided in the Oracle Critical Patch Update Advisory for July 2026. Administrators running the affected versions should consult that advisory and apply the corresponding fixes. At time of writing the NVD record status is "Received."
Sources
- Oracle Critical Patch Update Advisory – July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD – CVE-2026-60254: https://nvd.nist.gov/vuln/detail/CVE-2026-60254