Junglewise Threat Intelligence

CVE-2026-60309: Oracle Coherence compromise in Core component

CVE-2026-60309 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Coherence. Vendors: Oracle.

Executive brief

Oracle Coherence, a data grid solution used for high-speed data processing and application scaling, contains a critical vulnerability in its core component. An attacker with access to the local network segment where the software is running can completely take over the system. This could lead to the theft of sensitive data, disruption of business operations, and total loss of control over the affected environment.

Technical details

This vulnerability exists in the Core component of Oracle Coherence (Oracle Fusion Middleware). It is classified as easily exploitable and requires the attacker to have access to the physical communication segment (adjacent network) attached to the hardware where Oracle Coherence is executing. No authentication or user interaction is required for exploitation. A successful attack results in a complete compromise of the Oracle Coherence instance, impacting confidentiality, integrity, and availability. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats