SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60296 2026-07-21

Oracle Coherence Core Flaw (CVE-2026-60296) Allows Unauthenticated Takeover

"A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated network attacker fully compromise the product, earning a CVSS 3.1 base score of 9.8."

A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated network attacker fully compromise the product, earning a CVSS 3.1 base score of 9.8.

What Is It

CVE-2026-60296 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in complete takeover of Oracle Coherence.

The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects a network attack vector, low attack complexity, no required privileges, and no user interaction; with high impact to confidentiality, integrity, and availability.

Why It Matters

With a base score of 9.8 (CRITICAL) and full unauthenticated remote exploitation, this vulnerability offers attackers a direct path to seizing control of an affected Coherence instance. Because exploitation requires no credentials and no user interaction, any exposed TCP-reachable instance is at significant risk. There is no CISA KEV entry in the supplied source material, so active exploitation is not confirmed here; the severity alone warrants urgent attention.

What's Vulnerable

The following supported versions of Oracle Coherence are affected:

The vulnerable component is the Coherence Core.

Patch Status

Oracle addressed this vulnerability in its Critical Patch Update for July 2026. Administrators should apply the fixes described in the Oracle Critical Patch Update Advisory (cpujul2026) as the required remediation, prioritizing any internet- or network-reachable Coherence deployments given the unauthenticated attack vector.

Sources