SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60306 2026-07-21

CVE-2026-60306: Critical Unauthenticated Takeover Flaw in Oracle Coherence

"A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker with network access fully compromise the product over TCP."

A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated attacker with network access fully compromise the product over TCP.

What Is It

CVE-2026-60306 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. A successful attack can result in a complete takeover of Oracle Coherence.

The vulnerability carries a CVSS 3.1 Base Score of 9.8 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning it is network-reachable, low-complexity, requires no privileges and no user interaction, and fully impacts confidentiality, integrity, and availability.

Why It Matters

The combination of network attack vector, low complexity, and no authentication requirement makes this an attractive target. Because successful exploitation results in full takeover of the affected Coherence instance, an attacker gains complete control over the confidentiality, integrity, and availability of the system. Oracle's own description characterizing the flaw as "easily exploitable" underscores the urgency for exposed deployments.

What's Vulnerable

The affected product is Oracle Coherence (vendor: Oracle Corporation), a component of Oracle Fusion Middleware. The following supported versions are listed as affected:

Patch Status

The vulnerability was published on 2026-07-21 and is addressed in Oracle's July 2026 Critical Patch Update (CPU). Oracle references the CPU advisory (cpujul2026.html) as the source for remediation. Administrators running affected versions should apply the fixes provided in the July 2026 Critical Patch Update. No CISA KEV entry confirming active exploitation was supplied for this CVE at the time of writing.

Sources