A critical, easily exploitable flaw in Oracle Coherence lets an unauthenticated attacker take full control of the product over the network, earning a maximum-tier CVSS 9.8 rating.
What Is It
CVE-2026-60286 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. A successful attack results in complete takeover of the product. It carries a CVSS 3.1 Base Score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required.
Why It Matters
The vulnerability scores High across all three impact dimensions: Confidentiality, Integrity, and Availability. Because it requires no authentication, no privileges, and no user interaction, any exposed HTTP-reachable instance is at direct risk. Full takeover of a Coherence deployment, often used as an in-memory data grid underpinning critical applications, hands an attacker control over the data and services relying on it. The combination of maximum impact and trivial exploitability places this among the most urgent classes of remotely exploitable flaws.
What's Vulnerable
The affected product is Oracle Coherence (Oracle Corporation). Supported versions listed as affected are:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
Oracle addressed this vulnerability in the July 2026 Critical Patch Update. Administrators should apply the fixes referenced in Oracle's Critical Patch Update Advisory for the affected versions. No CISA KEV entry accompanies this record, so active exploitation is not confirmed in the supplied source material; given the 9.8 severity and unauthenticated remote reachability, patching should be treated as a priority.
Sources
- Oracle Critical Patch Update Advisory; July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60286: https://nvd.nist.gov/vuln/detail/CVE-2026-60286