SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60264 2026-07-21

CVE-2026-60264: Critical Unauthenticated Takeover in Oracle Coherence

"A critical, easily exploitable flaw in Oracle Coherence lets an unauthenticated attacker with HTTP/2 network access fully compromise the product, carrying a CVSS 3.1 base score of 9.8."

A critical, easily exploitable flaw in Oracle Coherence lets an unauthenticated attacker with HTTP/2 network access fully compromise the product, carrying a CVSS 3.1 base score of 9.8.

What Is It

CVE-2026-60264 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw allows an unauthenticated attacker with network access via HTTP/2 to compromise Oracle Coherence. Successful exploitation can result in complete takeover of the product. The CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects network attack vector, low attack complexity, no privileges required, and no user interaction.

Why It Matters

With a base score of 9.8 (CRITICAL) and full High impact to confidentiality, integrity, and availability, this is among the most severe classes of vulnerability. Oracle describes it as "easily exploitable," and because it requires no authentication and no user interaction over the network, an attacker only needs HTTP/2 reachability to the service. The result, takeover of Oracle Coherence, means an attacker can gain complete control of the affected instance.

What's Vulnerable

The affected product is Oracle Coherence (Oracle Corporation), component: Core. The supported versions listed as affected are:

Patch Status

This vulnerability was published as part of the Oracle Critical Patch Update for July 2026. Organizations running the affected Oracle Coherence versions should consult and apply the fixes referenced in Oracle's July 2026 Critical Patch Update advisory. No CISA KEV entry accompanies this record, so active exploitation is not confirmed in the supplied source material.

Sources