CVE-2026-60217
Oracle · Coherence
A critical vulnerability in the Oracle Coherence Core component allows an unauthenticated attacker to achieve full system takeover via network access.
Executive summary
A critical, unauthenticated remote takeover vulnerability in Oracle Coherence poses a severe risk of complete system compromise and cross-product exploitation.
Vulnerability
The vulnerability resides in the Core component of Oracle Coherence and permits an unauthenticated attacker with network access via TCP to execute unauthorized commands and seize control of the application.
Business impact
With a CVSS score of 10.0, this vulnerability presents an existential risk to the integrity of the affected Oracle Coherence environment. Exploitation allows for complete data exfiltration and total loss of system control. Furthermore, the capacity for scope change indicates that an attacker could leverage this entry point to compromise other integrated components within the Oracle Fusion Middleware stack.
Remediation
Immediate Action: Update all affected instances of Oracle Coherence to the latest patched versions as detailed in the July 2026 Oracle Critical Patch Update.
Proactive Monitoring: Review TCP traffic logs for anomalous patterns directed at the Coherence service and monitor for unauthorized changes to system configurations or unexpected new processes.
Compensating Controls: Ensure that Coherence services are not exposed to the public internet and utilize internal firewalls to restrict network access to trusted administrative and application nodes only.
Exploitation status
Public Exploit Available: No confirmed public exploit available.
Analyst recommendation
The severity of this vulnerability necessitates an emergency patching cycle. Organizations should isolate affected systems from the network until the vendor-supplied patches can be successfully deployed to eliminate the risk of remote takeover.