Junglewise Threat Intelligence

CVE-2026-60229: Oracle Coherence remote compromise in Core component

CVE-2026-60229 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a distributed data grid solution used for high-speed data processing and application scaling, contains a critical security flaw. An unauthorized attacker can remotely take full control of the Coherence environment over the network without needing any login credentials. This could lead to the complete theft of sensitive data, disruption of business operations, and total loss of system integrity.

Technical details

A critical vulnerability exists in the Core component of Oracle Coherence (Oracle Fusion Middleware). The flaw is easily exploitable by an unauthenticated attacker with network access via the TCP protocol. While the specific vulnerability class (e.g., deserialization or improper input validation) is not explicitly detailed in the advisory, the impact is a complete compromise of Confidentiality, Integrity, and Availability (CIA triad), effectively allowing a full system takeover. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation guidance.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication of the CVE record and Oracle advisory.

References

Related threats