SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60279 2026-07-21

CVE-2026-60279: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker take full control of the product over the network via HTTP, patched in Oracle's July 2026 Critical Patch Update."

A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker take full control of the product over the network via HTTP, patched in Oracle's July 2026 Critical Patch Update.

What Is It

CVE-2026-60279 is a critical flaw in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, the vulnerability is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. A successful attack can result in complete takeover of the product.

The issue carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low attack complexity, no privileges or user interaction required, with high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of unauthenticated network access, low exploitation complexity, and full takeover impact makes this among the most severe class of vulnerabilities. No credentials or user interaction are needed, which lowers the barrier for exploitation against internet- or network-exposed Coherence deployments. The maximum-tier impact across all three security properties means a successful attacker can read data, modify it, and disrupt availability.

What's Vulnerable

The affected product is Oracle Coherence (Oracle Fusion Middleware, Core component). The supported versions listed as affected are:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (CPU). Administrators running any of the affected versions should apply the fixes referenced in the Oracle July 2026 CPU advisory. The supplied source material does not include a CISA KEV entry for this CVE, so there is no confirmation of active exploitation in the data provided.

Sources