SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60276 2026-07-21

CVE-2026-60276: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker take over the product remotely over HTTPS, disclosed in Oracle's July 2026 Critical Patch Update."

A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker take over the product remotely over HTTPS, disclosed in Oracle's July 2026 Critical Patch Update.

What Is It

CVE-2026-60276 is a critical vulnerability in the Core component of Oracle Coherence, a product within Oracle Fusion Middleware. According to Oracle, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTPS to compromise Oracle Coherence. A successful attack can result in complete takeover of the product.

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That combination, network attack vector, low complexity, no privileges, and no user interaction required, reflects a flaw that is trivial to reach and delivers high impact to confidentiality, integrity, and availability.

Why It Matters

An unauthenticated, network-reachable flaw scoring 9.8 with full impact across all three security properties represents worst-case risk. No credentials and no user interaction are needed, and the payoff is takeover of the affected Coherence instance. Oracle's own description labels it easily exploitable, meaning exposed instances are attractive targets.

What's Vulnerable

The following supported Oracle Coherence versions are affected:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Organizations running any affected version should apply the fixes referenced in that advisory. At the time of this record (NVD status: Received), there is no CISA KEV entry supplied for this CVE, so active exploitation is not confirmed in the available source material.

Sources