Oracle has disclosed a critical (CVSS 9.8) vulnerability in Oracle Coherence that lets an unauthenticated, network-based attacker fully compromise the product.
What Is It
CVE-2026-60269 is a critical vulnerability in the Oracle Coherence product of Oracle Fusion Middleware, in the Core component. Per Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in complete takeover of Oracle Coherence.
The vulnerability carries a CVSS 3.1 Base Score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting high impact to confidentiality, integrity, and availability.
Why It Matters
This vulnerability combines the worst-case set of exploitability traits: network attack vector, low attack complexity, no privileges required, and no user interaction. That means an attacker needs only TCP network reach to a vulnerable instance to attempt full takeover. Oracle explicitly characterizes it as "easily exploitable," and the resulting compromise affects all three security pillars; data confidentiality, integrity, and system availability.
There is no CISA KEV entry in the supplied source material, so active exploitation is not confirmed at this time. However, the severity and low barrier to exploitation warrant prompt attention.
What's Vulnerable
The affected product is Oracle Coherence (vendor: Oracle Corporation), part of Oracle Fusion Middleware. The supported versions listed as affected are:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
The vulnerability was published on 2026-07-21 with an NVD status of "Received." The fix is addressed through Oracle's Critical Patch Update for July 2026. Organizations running affected versions should consult the Oracle Critical Patch Update Advisory and apply the relevant fixes.
Sources
- Oracle Critical Patch Update Advisory - July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60269, https://nvd.nist.gov/vuln/detail/CVE-2026-60269