SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60286 2026-07-21

CVE-2026-60286: Critical Unauthenticated Takeover in Oracle Coherence

"A critical, easily exploitable flaw in Oracle Coherence lets an unauthenticated attacker take full control of the product over the network, earning a maximum-tier CVSS 9.8 rating."

A critical, easily exploitable flaw in Oracle Coherence lets an unauthenticated attacker take full control of the product over the network, earning a maximum-tier CVSS 9.8 rating.

What Is It

CVE-2026-60286 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. A successful attack results in complete takeover of the product. It carries a CVSS 3.1 Base Score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required.

Why It Matters

The vulnerability scores High across all three impact dimensions: Confidentiality, Integrity, and Availability. Because it requires no authentication, no privileges, and no user interaction, any exposed HTTP-reachable instance is at direct risk. Full takeover of a Coherence deployment, often used as an in-memory data grid underpinning critical applications, hands an attacker control over the data and services relying on it. The combination of maximum impact and trivial exploitability places this among the most urgent classes of remotely exploitable flaws.

What's Vulnerable

The affected product is Oracle Coherence (Oracle Corporation). Supported versions listed as affected are:

Patch Status

Oracle addressed this vulnerability in the July 2026 Critical Patch Update. Administrators should apply the fixes referenced in Oracle's Critical Patch Update Advisory for the affected versions. No CISA KEV entry accompanies this record, so active exploitation is not confirmed in the supplied source material; given the 9.8 severity and unauthenticated remote reachability, patching should be treated as a priority.

Sources