SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60274 2026-07-21

CVE-2026-60274: Critical Unauthenticated Takeover in Oracle Coherence

"A critical, easily exploitable flaw in Oracle Coherence lets an unauthenticated network attacker fully compromise the product, carrying a CVSS 3.1 base score of 9.8."

The article:

CVE-2026-60274: Critical Unauthenticated Takeover in Oracle Coherence

A critical, easily exploitable flaw in Oracle Coherence lets an unauthenticated network attacker fully compromise the product, carrying a CVSS 3.1 base score of 9.8.

What Is It

CVE-2026-60274 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in a complete takeover of the product.

The CVSS 3.1 vector, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflects a network attack vector, low attack complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.

Why It Matters

With a base score of 9.8 (CRITICAL), this is among the most severe class of vulnerabilities. The combination of remote reachability over TCP, no authentication requirement, and full compromise of the target makes it an attractive candidate for attackers. Oracle Coherence is an in-memory data grid commonly deployed within enterprise middleware environments, so exposure can sit close to sensitive application data.

Note: The supplied source material does not include a CISA KEV entry for this CVE, so active exploitation is not confirmed by KEV at this time.

What's Vulnerable

The following supported Oracle Coherence versions are listed as affected:

The affected component is identified as Core.

Patch Status

The vulnerability was published on 2026-07-21 with a status of "Received." Oracle references its July 2026 Critical Patch Update advisory as the source for this issue. Organizations running affected versions should consult that advisory and apply the corresponding Critical Patch Update fixes for Oracle Coherence.

Sources