A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker with network access fully compromise the product over TCP.
What Is It
CVE-2026-60256 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Oracle describes it as an easily exploitable flaw that allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in complete takeover of the product.
The flaw carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required, with high impacts to confidentiality, integrity, and availability.
Why It Matters
The combination of remote reachability, no authentication, low attack complexity, and a full-takeover outcome places this at the top of the severity scale. An attacker who can reach an affected Coherence instance over TCP can compromise it without credentials or user interaction, gaining high impact across confidentiality, integrity, and availability; effectively controlling the affected service.
What's Vulnerable
The following supported Oracle Coherence versions are affected:
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
The vulnerability was disclosed by Oracle (source identifier [email protected]) and published on 2026-07-21. It is addressed in the Oracle Critical Patch Update for July 2026. Administrators should consult the Oracle Critical Patch Update Advisory and apply the corresponding fixes for affected Coherence versions.
Note: No CISA KEV entry was supplied with this record, so active exploitation is not confirmed by KEV at this time.
Sources
- Oracle Critical Patch Update Advisory, July 2026, https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60256, https://nvd.nist.gov/vuln/detail/CVE-2026-60256