A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker with network access fully compromise affected systems over TCP.
What Is It
CVE-2026-60287 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful exploitation can result in a complete takeover of Oracle Coherence. The flaw carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required.
Why It Matters
This vulnerability combines the worst attributes for defenders: remote, network-reachable, unauthenticated, and low-complexity, with high impact across confidentiality, integrity, and availability. Because exploitation requires no credentials and no user interaction, any exposed Coherence instance reachable over TCP is at direct risk of full compromise. The 9.8 base score places it in the highest-priority remediation tier.
What's Vulnerable
The affected product is Oracle Coherence (Oracle Corporation), within Oracle Fusion Middleware. The following supported versions are listed as affected:
- 12.2.1.4.0
- 14.1.1.0.0
- 14.1.2.0.0
- 15.1.1.0.0
Patch Status
Oracle addresses this issue in its July 2026 Critical Patch Update. Organizations running any affected version should apply the fixes referenced in the Oracle Critical Patch Update advisory as a priority. No CISA KEV entry confirming active exploitation was supplied with this record; the assessment here is based on the NVD/Oracle data. Given the severity and ease of exploitation, patching should not be deferred.