SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60257 2026-07-21

CVE-2026-60257: Critical Unauthenticated Takeover in Oracle Coherence

"A critical, easily exploitable flaw in Oracle Coherence lets an unauthenticated attacker fully compromise the product over the network, earning a CVSS 3.1 base score of 9.8."

A critical, easily exploitable flaw in Oracle Coherence lets an unauthenticated attacker fully compromise the product over the network, earning a CVSS 3.1 base score of 9.8.

What Is It

CVE-2026-60257 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful exploitation can result in a complete takeover of the product. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting network attack vector, low complexity, no privileges, and no user interaction.

Why It Matters

With a base score of 9.8 (Critical), this is about as severe as vulnerabilities get. The combination of network reachability, no authentication requirement, and low attack complexity means an attacker needs only TCP access to a vulnerable instance to fully compromise it; impacting confidentiality, integrity, and availability all at the "High" level. Oracle Coherence is commonly deployed as an in-memory data grid underpinning application infrastructure, so a takeover can expose sensitive data and disrupt dependent services.

Note: No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation at this time.

What's Vulnerable

The following supported versions of Oracle Coherence (Oracle Corporation) are affected:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Administrators should apply the fixes documented in the Oracle CPU advisory for July 2026 to remediate affected Coherence deployments. Given the unauthenticated, network-facing nature of the flaw, patching should be prioritized.

Sources