Junglewise Threat Intelligence

CVE-2026-60276: Oracle Coherence remote compromise in Core component

CVE-2026-60276 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a data grid solution used for high-speed data processing and storage, contains a critical security flaw. An unauthorized attacker can remotely take full control of the system over the network. This could lead to the complete theft of sensitive data, unauthorized modification of information, or a total shutdown of the service.

Technical details

A vulnerability exists in the Core component of Oracle Coherence (part of Oracle Fusion Middleware). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTPS. While the specific vulnerability class (e.g., deserialization or injection) is not explicitly named in the advisory, the impact is a complete compromise of confidentiality, integrity, and availability, effectively allowing a full system takeover. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats