SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60267 2026-07-21

CVE-2026-60267: Critical Unauthenticated Flaw in Oracle Coherence

"A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated network attacker read and alter all accessible data, scoring 9.1 on CVSS 3.1."

A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated network attacker read and alter all accessible data, scoring 9.1 on CVSS 3.1.

What Is It

CVE-2026-60267 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TLS to compromise Oracle Coherence. It carries a CVSS 3.1 base score of 9.1 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, network attack vector, low complexity, and no privileges or user interaction required.

Why It Matters

Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, or all Oracle Coherence accessible data, as well as unauthorized read access to critical data or complete access to all Oracle Coherence accessible data. The CVSS breakdown reflects HIGH confidentiality and integrity impacts (availability is rated NONE). Because the attack requires no authentication and no user interaction over the network, the barrier to exploitation is low, making this a high-priority concern for any exposed deployment.

What's Vulnerable

The affected product is Oracle Coherence (Oracle Corporation) within Oracle Fusion Middleware. Per the NVD record, the affected supported versions are:

Patch Status

The vulnerability was published on 2026-07-21 with an NVD status of "Received." The single reference points to Oracle's Critical Patch Update advisory for July 2026 (cpujul2026.html), where remediation is addressed. Administrators should consult that advisory and apply the corresponding fixes. The supplied source material contains no CISA KEV entry, so there is no confirmation of active exploitation in the provided data.

Sources