Junglewise Threat Intelligence

CVE-2026-60288: Oracle Coherence remote compromise in Core component

CVE-2026-60288 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a data grid solution used for high-speed data processing and application scaling, contains a critical vulnerability in its core component. An unauthorized attacker can exploit this over the network to gain full control of the system. This could lead to a complete loss of data confidentiality, unauthorized modification of information, and a total disruption of services.

Technical details

A vulnerability exists in the Core component of Oracle Coherence (Oracle Fusion Middleware). The flaw is easily exploitable by an unauthenticated attacker with network access via TCP. Successful exploitation allows for a complete takeover of the Oracle Coherence instance, impacting confidentiality, integrity, and availability. The vulnerability has a CVSS 3.1 base score of 9.8. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: advisory: Initial publication of CVE-2026-60288 by Oracle and NVD.

References

Related threats