SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60285 2026-07-21

CVE-2026-60285: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated network attacker fully take over the affected middleware."

A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated network attacker fully take over the affected middleware.

What Is It

CVE-2026-60285 is a critical (CVSS 3.1 base score 9.8) vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to the NVD record, the flaw allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence, with successful attacks resulting in complete takeover of the product. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects network-based, low-complexity exploitation requiring no privileges or user interaction, with high impact to confidentiality, integrity, and availability.

Why It Matters

Oracle describes the vulnerability as "easily exploitable," and its 9.8 rating places it among the most severe class of flaws. Because exploitation requires no authentication and no user interaction, any exposed Coherence instance reachable over TCP is at direct risk of full compromise. A takeover affects all three security pillars, data confidentiality, data integrity, and service availability, making this a high-priority remediation target for organizations running Coherence in their middleware stack.

What's Vulnerable

The NVD record lists the following affected Oracle Coherence versions:

The vulnerability resides in the Coherence Core component. No public exploit or active-exploitation status is confirmed in the supplied source material (no CISA KEV entry was provided).

Patch Status

The fix is addressed in Oracle's Critical Patch Update for July 2026. The NVD entry was published on 2026-07-21 and references Oracle's official Critical Patch Update advisory as the sole remediation source. Organizations running affected versions should apply the July 2026 CPU updates without delay.

Sources