Junglewise Threat Intelligence

CVE-2026-60210: Oracle Coherence remote compromise in Core component

CVE-2026-60210 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a widely used data grid solution for high-speed data processing and application scaling, contains a critical security vulnerability in its core component. An unauthenticated attacker can exploit this flaw over a network to gain full control of the Coherence environment. This could lead to the theft of sensitive data, disruption of business operations, and total system takeover.

Technical details

This vulnerability exists within the Core component of Oracle Coherence (Fusion Middleware). It is classified as easily exploitable, requiring no authentication or user interaction (PR:N/UI:N). An attacker can exploit this flaw by sending malicious TCP traffic to the affected service. Successful exploitation results in a complete compromise of confidentiality, integrity, and availability, effectively allowing a full takeover of the Oracle Coherence instance. The vulnerability affects versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: advisory: Initial advisory published by Oracle and NVD.

References

Related threats