SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60299 2026-07-21

CVE-2026-60299: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated network attacker fully compromise and take over affected systems, carrying a maximum-tier CVSS score of 9.8."

The article:

CVE-2026-60299: Critical Unauthenticated Takeover Flaw in Oracle Coherence

A critical, easily exploitable vulnerability in Oracle Coherence lets an unauthenticated network attacker fully compromise and take over affected systems, carrying a maximum-tier CVSS score of 9.8.

What Is It

CVE-2026-60299 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in complete takeover of Oracle Coherence.

The vulnerability holds a CVSS 3.1 Base Score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting high impact to confidentiality, integrity, and availability. It requires no privileges, no user interaction, and can be exploited across a network with low attack complexity.

Why It Matters

This flaw combines the worst attributes for defenders: it is remotely reachable over the network, requires no authentication, and is described by the vendor as easily exploitable. Successful exploitation yields full takeover of the affected Coherence instance, threatening data confidentiality, integrity, and service availability alike. Oracle Coherence is used as an in-memory data grid in enterprise middleware deployments, making exposed instances high-value targets.

What's Vulnerable

The affected product is Oracle Coherence (Oracle Fusion Middleware), component Core. The supported versions confirmed affected are:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Administrators running the affected versions should apply the fixes from the Oracle Critical Patch Update advisory without delay. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the available source material.

Sources