SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60275 2026-07-21

CVE-2026-60275: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated attacker with network access fully compromise the product over HTTP, carrying a CVSS 3.1 base score of 9.8."

A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated attacker with network access fully compromise the product over HTTP, carrying a CVSS 3.1 base score of 9.8.

What Is It

CVE-2026-60275 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. A successful attack results in complete takeover of the product. The issue was published on July 21, 2026, and is scored under the CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Why It Matters

With a base score of 9.8 (CRITICAL), this vulnerability sits at the top of the severity scale. The attack vector is network-based, attack complexity is low, and no privileges or user interaction are required; meaning an attacker only needs HTTP reachability to the affected service. The impact is total: high confidentiality, integrity, and availability impact, up to and including full takeover of the Coherence instance. This combination of easy exploitation and complete compromise makes it a high-priority patching target for any organization running affected versions.

What's Vulnerable

The vulnerability affects the following supported Oracle Coherence versions:

The affected component is Core, and the vendor is Oracle Corporation.

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running any affected version should apply the fixes referenced in the Oracle Critical Patch Update Advisory (July 2026) without delay. No CISA KEV entry accompanies the supplied source material, so active exploitation is not confirmed by the data provided here.

Sources