A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated network attacker read and alter all accessible data, scoring 9.1 on CVSS 3.1.
What Is It
CVE-2026-60267 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TLS to compromise Oracle Coherence. It carries a CVSS 3.1 base score of 9.1 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, network attack vector, low complexity, and no privileges or user interaction required.
Why It Matters
Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, or all Oracle Coherence accessible data, as well as unauthorized read access to critical data or complete access to all Oracle Coherence accessible data. The CVSS breakdown reflects HIGH confidentiality and integrity impacts (availability is rated NONE). Because the attack requires no authentication and no user interaction over the network, the barrier to exploitation is low, making this a high-priority concern for any exposed deployment.
What's Vulnerable
The affected product is Oracle Coherence (Oracle Corporation) within Oracle Fusion Middleware. Per the NVD record, the affected supported versions are:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
The vulnerability was published on 2026-07-21 with an NVD status of "Received." The single reference points to Oracle's Critical Patch Update advisory for July 2026 (cpujul2026.html), where remediation is addressed. Administrators should consult that advisory and apply the corresponding fixes. The supplied source material contains no CISA KEV entry, so there is no confirmation of active exploitation in the provided data.