A critical, unauthenticated remote vulnerability in Oracle Coherence lets network attackers fully take over affected Fusion Middleware deployments.
What Is It
CVE-2026-60278 is a critical flaw in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, the vulnerability is "easily exploitable" and allows an unauthenticated attacker with network access over HTTP to compromise Oracle Coherence. A successful attack results in complete takeover of the product. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of network attack vector, low attack complexity, and no required privileges or user interaction means this vulnerability can be exploited remotely by anyone who can reach the service over HTTP, no credentials needed. Because a successful attack yields full takeover across all three security dimensions, exposed Coherence instances represent a high-value target for attackers seeking to compromise middleware infrastructure. Oracle Coherence is commonly deployed as an in-memory data grid supporting business-critical applications, amplifying the potential blast radius.
What's Vulnerable
The affected product is Oracle Coherence within Oracle Fusion Middleware. According to Oracle, the impacted supported versions are:
- Oracle Coherence 12.2.1.4.0
- Oracle Coherence 14.1.1.0.0
The vulnerable functionality resides in the Core component.
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running the affected versions should apply the fixes referenced in Oracle's Critical Patch Update advisory (cpujul2026) as the required remediation. This CVE was published on 2026-07-21 and, at the time of writing, does not appear in the CISA Known Exploited Vulnerabilities catalog; no confirmation of active exploitation is present in the supplied source material.
Sources
- Oracle Critical Patch Update Advisory; July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60278: https://nvd.nist.gov/vuln/detail/CVE-2026-60278