The article:
CVE-2026-60274: Critical Unauthenticated Takeover in Oracle Coherence
A critical, easily exploitable flaw in Oracle Coherence lets an unauthenticated network attacker fully compromise the product, carrying a CVSS 3.1 base score of 9.8.
What Is It
CVE-2026-60274 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in a complete takeover of the product.
The CVSS 3.1 vector, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflects a network attack vector, low attack complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.
Why It Matters
With a base score of 9.8 (CRITICAL), this is among the most severe class of vulnerabilities. The combination of remote reachability over TCP, no authentication requirement, and full compromise of the target makes it an attractive candidate for attackers. Oracle Coherence is an in-memory data grid commonly deployed within enterprise middleware environments, so exposure can sit close to sensitive application data.
Note: The supplied source material does not include a CISA KEV entry for this CVE, so active exploitation is not confirmed by KEV at this time.
What's Vulnerable
The following supported Oracle Coherence versions are listed as affected:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
The affected component is identified as Core.
Patch Status
The vulnerability was published on 2026-07-21 with a status of "Received." Oracle references its July 2026 Critical Patch Update advisory as the source for this issue. Organizations running affected versions should consult that advisory and apply the corresponding Critical Patch Update fixes for Oracle Coherence.