A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker take full control of the product over the network via HTTP, patched in Oracle's July 2026 Critical Patch Update.
What Is It
CVE-2026-60279 is a critical flaw in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, the vulnerability is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. A successful attack can result in complete takeover of the product.
The issue carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low attack complexity, no privileges or user interaction required, with high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of unauthenticated network access, low exploitation complexity, and full takeover impact makes this among the most severe class of vulnerabilities. No credentials or user interaction are needed, which lowers the barrier for exploitation against internet- or network-exposed Coherence deployments. The maximum-tier impact across all three security properties means a successful attacker can read data, modify it, and disrupt availability.
What's Vulnerable
The affected product is Oracle Coherence (Oracle Fusion Middleware, Core component). The supported versions listed as affected are:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update (CPU). Administrators running any of the affected versions should apply the fixes referenced in the Oracle July 2026 CPU advisory. The supplied source material does not include a CISA KEV entry for this CVE, so there is no confirmation of active exploitation in the data provided.
Sources
- Oracle Critical Patch Update Advisory – July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60279, https://nvd.nist.gov/vuln/detail/CVE-2026-60279