Oracle's July 2026 Critical Patch Update discloses CVE-2026-60262, a CVSS 9.8 vulnerability in Oracle Coherence that lets an unauthenticated attacker fully compromise the product over the network.
What Is It
CVE-2026-60262 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in complete takeover of the product, with high impact to confidentiality, integrity, and availability.
Why It Matters
The vulnerability carries a CVSS 3.1 Base Score of 9.8 (CRITICAL) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. This combination, network attack vector, low attack complexity, no privileges required, and no user interaction, means an attacker needs only network reachability to the service. The exploitability score is a maximum 3.9, underscoring how straightforward exploitation is. Because Coherence is a distributed in-memory data grid often deployed in high-value application tiers, a full takeover could expose sensitive data and disrupt dependent services.
What's Vulnerable
The following supported versions of Oracle Coherence are affected:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Administrators should apply the fixes referenced in the Oracle Critical Patch Update advisory. The supplied source material contains no CISA KEV entry for this CVE, so there is no confirmation of active exploitation or a required-action due date at this time. The NVD record status is "Received," indicating the entry is still awaiting full analysis.