SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60259 2026-07-21

Oracle Coherence Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60259)

"A critical, easily exploitable flaw in Oracle Coherence lets an unauthenticated attacker take full control of the product over the network, scoring a near-maximum CVSS 9.8."

A critical, easily exploitable flaw in Oracle Coherence lets an unauthenticated attacker take full control of the product over the network, scoring a near-maximum CVSS 9.8.

What Is It

CVE-2026-60259 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. A successful attack results in full takeover of the product. It carries a CVSS 3.1 base score of 9.8 (CRITICAL), with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning no privileges, no user interaction, and low attack complexity, with high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of network-based exploitation, no authentication requirement, low complexity, and a total-takeover outcome places this at the top of the severity scale. An attacker who can reach an exposed Coherence instance over HTTP can fully compromise it without credentials, threatening the confidentiality, integrity, and availability of the data and services it supports. There is no CISA KEV entry in the supplied material, so active exploitation is not confirmed here, but the 9.8 rating warrants urgent attention regardless.

What's Vulnerable

The affected product is Oracle Coherence (vendor: Oracle Corporation). Per the NVD record, the supported versions affected are:

Patch Status

The vulnerability was published on 2026-07-21 with an NVD status of "Received." The sole reference is Oracle's Critical Patch Update advisory for July 2026, which is where remediation guidance and fixes for this issue are provided. Organizations running affected Coherence versions should consult that advisory and apply the corresponding Critical Patch Update.

Sources