SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60280 2026-07-21

Oracle Coherence Remote Takeover Flaw — CVE-2026-60280

"A critical, unauthenticated vulnerability in Oracle Coherence lets attackers take over affected systems over the network, and it carries a maximum-tier CVSS score of 9.8."

A critical, unauthenticated vulnerability in Oracle Coherence lets attackers take over affected systems over the network, and it carries a maximum-tier CVSS score of 9.8.

What Is It

CVE-2026-60280 is a critical flaw in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the vulnerability is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP/2 to compromise Oracle Coherence. A successful attack can result in full takeover of the product. It carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required.

Why It Matters

This is about as severe as a vulnerability gets. No authentication and no user interaction are needed, the attack traverses the network over HTTP/2, and the impact spans all three pillars; high confidentiality, integrity, and availability. Because success yields complete takeover of Oracle Coherence, any exposed and unpatched instance represents a direct path to compromise of the underlying middleware environment.

What's Vulnerable

The affected product is Oracle Coherence (vendor: Oracle Corporation) within Oracle Fusion Middleware. The supported versions listed as affected are:

Patch Status

The vulnerability is addressed in Oracle's July 2026 Critical Patch Update. Organizations running any of the affected versions should apply the fixes from that Critical Patch Update without delay, given the maximum-severity rating and the ease of exploitation. No CISA KEV entry accompanies the supplied material, so active exploitation is not confirmed here.

Sources