SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60258 2026-07-21

CVE-2026-60258: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"A critical vulnerability in Oracle Coherence lets an unauthenticated attacker with network access fully compromise the product over TCP, scoring a maximum-tier 9.8 CVSS."

A critical vulnerability in Oracle Coherence lets an unauthenticated attacker with network access fully compromise the product over TCP, scoring a maximum-tier 9.8 CVSS.

What Is It

CVE-2026-60258 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks can result in a complete takeover of the product.

The CVSS 3.1 base score is 9.8 (CRITICAL), with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. This reflects network attack vector, low attack complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of unauthenticated network exploitation and full takeover makes this an especially high-risk flaw. With no authentication or user interaction needed and low attack complexity, an exposed and unpatched instance is a straightforward target. The high impact across all three security dimensions means an attacker who succeeds gains control over the confidentiality, integrity, and availability of the affected Coherence deployment.

What's Vulnerable

The affected product is Oracle Coherence (vendor: Oracle Corporation), within Oracle Fusion Middleware. Per the NVD record, the affected supported versions are:

Patch Status

This vulnerability was addressed in the Oracle Critical Patch Update of July 2026. Organizations running affected Coherence versions should consult Oracle's July 2026 CPU advisory and apply the relevant fixes. No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the provided source material.

Sources