SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60272 2026-07-21

CVE-2026-60272: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"Oracle's July 2026 Critical Patch Update discloses CVE-2026-60272, a CVSS 9.8 vulnerability in Oracle Coherence that lets an unauthenticated attacker fully compromise the product over the network."

Oracle's July 2026 Critical Patch Update discloses CVE-2026-60272, a CVSS 9.8 vulnerability in Oracle Coherence that lets an unauthenticated attacker fully compromise the product over the network.

What Is It

CVE-2026-60272 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. A successful attack can result in complete takeover of the product.

The issue carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required, with high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of no authentication, low attack complexity, and HTTP-based network reach makes this an attractive target. The impact profile is total: an attacker can undermine the confidentiality, integrity, and availability of the affected Coherence instance, up to and including full takeover. Coherence is commonly deployed as an in-memory data grid underpinning Fusion Middleware and enterprise applications, so a compromise can expose sensitive cached data and disrupt dependent services.

Note: The supplied CISA KEV entry is empty, so there is no confirmation of active exploitation in the source material.

What's Vulnerable

The affected product is Oracle Coherence (Oracle Corporation). The following supported versions are listed as affected:

Patch Status

Oracle addresses CVE-2026-60272 in its July 2026 Critical Patch Update (cpujul2026). Organizations running any affected version should apply the fixes from the Oracle CPU advisory. The NVD record was published 2026-07-21 with a status of "Received," reflecting an initial disclosure aligned to the CPU release.

Sources