Junglewise Threat Intelligence

CVE-2026-60227: Oracle Coherence remote compromise in Core component

CVE-2026-60227 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

A critical vulnerability has been identified in Oracle Coherence, a data grid solution used for high-speed data processing and storage in enterprise environments. An unauthenticated attacker can exploit this flaw over a network to gain full control of the affected system. This could lead to the complete theft of sensitive data, unauthorized modification of information, or a total shutdown of the service, significantly impacting business operations and data integrity.

Technical details

This vulnerability exists within the Core component of Oracle Coherence (Oracle Fusion Middleware). It is classified as easily exploitable, requiring no authentication or user interaction. An attacker can exploit the flaw by sending malicious requests over the network via TCP. A successful exploit results in a complete takeover of the Oracle Coherence instance, providing the attacker with full Confidentiality, Integrity, and Availability (CIA) impact. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.

References

Related threats