A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated attacker with network access fully compromise the product over HTTP, carrying a CVSS 3.1 base score of 9.8.
What Is It
CVE-2026-60275 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. A successful attack results in complete takeover of the product. The issue was published on July 21, 2026, and is scored under the CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Why It Matters
With a base score of 9.8 (CRITICAL), this vulnerability sits at the top of the severity scale. The attack vector is network-based, attack complexity is low, and no privileges or user interaction are required; meaning an attacker only needs HTTP reachability to the affected service. The impact is total: high confidentiality, integrity, and availability impact, up to and including full takeover of the Coherence instance. This combination of easy exploitation and complete compromise makes it a high-priority patching target for any organization running affected versions.
What's Vulnerable
The vulnerability affects the following supported Oracle Coherence versions:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
The affected component is Core, and the vendor is Oracle Corporation.
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running any affected version should apply the fixes referenced in the Oracle Critical Patch Update Advisory (July 2026) without delay. No CISA KEV entry accompanies the supplied source material, so active exploitation is not confirmed by the data provided here.
Sources
- Oracle Critical Patch Update Advisory - July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60275 (source: [email protected])