SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60297 2026-07-21

CVE-2026-60297: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker with network access take over the product over TCP."

A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker with network access take over the product over TCP.

What Is It

CVE-2026-60297 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful exploitation can result in a full takeover of the product.

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning it is network-reachable, low-complexity, requires no privileges and no user interaction, and delivers high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of no authentication, low attack complexity, and network reachability over TCP makes this an attractive target. A successful attack yields complete takeover of the affected Coherence instance, exposing sensitive data, allowing tampering, and threatening availability. Any internet- or network-exposed Coherence deployment on an affected version should be treated as high-risk.

What's Vulnerable

The following supported versions of Oracle Coherence (Oracle Fusion Middleware, Core component) are affected:

Patch Status

This CVE was published July 21, 2026 and addressed in Oracle's July 2026 Critical Patch Update. Organizations running affected versions should apply the fixes from Oracle's Critical Patch Update advisory. No CISA KEV entry confirming active exploitation was supplied with this record, so exploitation status is not established here.

Sources