SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60290 2026-07-21

CVE-2026-60290: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"Oracle's July 2026 Critical Patch Update discloses CVE-2026-60290, a CVSS 9.8 vulnerability that lets an unauthenticated attacker take over Oracle Coherence over the network."

Oracle's July 2026 Critical Patch Update discloses CVE-2026-60290, a CVSS 9.8 vulnerability that lets an unauthenticated attacker take over Oracle Coherence over the network.

What Is It

CVE-2026-60290 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. A successful attack can result in complete takeover of the product.

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of factors here is about as severe as it gets. No authentication is needed, no user interaction is required, and the attack can be launched remotely over HTTP with low complexity. Because a successful exploit yields full takeover of Oracle Coherence, an in-memory data grid often embedded in business-critical middleware, the potential blast radius spans confidentiality, integrity, and availability equally. There is no active-exploitation confirmation in the supplied data (no CISA KEV entry was provided), but the risk profile alone warrants urgent attention.

What's Vulnerable

The affected product is Oracle Coherence (Oracle Fusion Middleware), Core component. The supported versions listed as affected are:

Patch Status

Oracle addresses CVE-2026-60290 in its July 2026 Critical Patch Update (published July 21, 2026). Administrators running any affected version should apply the fixes referenced in the Oracle Critical Patch Update advisory without delay. The NVD record was in "Received" status at the time of writing, with Oracle as the primary source.

Sources