SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60288 2026-07-21

Oracle Coherence Critical Flaw (CVE-2026-60288): Unauthenticated Takeover

"Oracle disclosed CVE-2026-60288, a critical (CVSS 9.8) vulnerability in Oracle Coherence that lets an unauthenticated attacker take over the product over the network."

Oracle disclosed CVE-2026-60288, a critical (CVSS 9.8) vulnerability in Oracle Coherence that lets an unauthenticated attacker take over the product over the network.

What Is It

CVE-2026-60288 is a vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in full takeover of Oracle Coherence, with high impact to confidentiality, integrity, and availability.

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL), vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required.

Why It Matters

The combination of network reachability, no authentication, low attack complexity, and full compromise makes this among the most severe class of vulnerabilities. Because exploitation requires no credentials and no user interaction, any exposed Coherence instance is a direct target. Successful attacks yield complete takeover of the affected Coherence deployment.

What's Vulnerable

Oracle Coherence (Oracle Corporation) is affected in the following supported versions:

The affected component is Core.

Patch Status

The vulnerability is addressed in Oracle's July 2026 Critical Patch Update. Administrators running any of the affected versions should apply the fixes referenced in the Oracle Critical Patch Update advisory. No CISA KEV entry accompanied this record, so active exploitation is not confirmed in the supplied source material.

Sources