CVE-2026-60211
Oracle · Coherence
A vulnerability in the Oracle Coherence Core component allows an unauthenticated attacker on the physical communication segment to take over the software.
Executive summary
An unauthenticated attacker with physical network segment access can exploit this vulnerability to take over Oracle Coherence.
Vulnerability
This is an easily exploitable flaw in the Core component of Oracle Coherence. It allows an unauthenticated attacker who has access to the physical communication segment attached to the hardware to compromise the application.
Business impact
By allowing unauthenticated access to the underlying hardware segment, this vulnerability poses a severe threat to the overall security posture of the Oracle Coherence environment. A successful exploit results in total system takeover, which could lead to significant data loss or service disruption, justifying the 8.8 CVSS score.
Remediation
Immediate Action: Review the Oracle July 2026 Critical Patch Update and apply the required security patches to all affected Coherence deployments.
Proactive Monitoring: Monitor network traffic for unusual activity on the communication segments where Coherence is deployed and restrict physical access to these segments as much as possible.
Compensating Controls: Implement network segmentation and strong access controls to ensure that only authorized devices can communicate with the hardware segments hosting Oracle Coherence.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Security teams must prioritize patching this vulnerability to prevent unauthorized access. Given the requirement for network segment access, tightening physical and logical access controls to the infrastructure is a critical secondary defense measure.