External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60221

Oracle Coherence is a distributed data grid and caching layer typically deployed in internal application tiers, backend clusters, or middleware environments. While it utilizes TCP network communication, it is rarely exposed directly to the public internet in standard deployments, usually residing behind application servers or within protected internal network segments.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware, that could allow an unauthenticated attacker to compromise the system remotely via TCP. The potential impact of successful exploitation is a complete takeover of the Oracle Coherence system, with significant implications for data confidentiality, integrity, and availability.

  • Unauthenticated network access can fully compromise Coherence.
  • It enables remote attackers to gain full system control.
  • Confirm relevance and exposure of Oracle Coherence.

Attack Path

How an attacker could exploit the issue

An attacker can reach Oracle Coherence over the network and trigger a vulnerability in its core component. This requires no authentication and can lead to a complete takeover of the Coherence system.

  • Attacker must have network access.
  • Vulnerability triggered via TCP.
  • Risk of system takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via TCP could compromise Oracle Coherence, potentially leading to a full takeover of the system when supported by the advisory.

  • Oracle Coherence system data.
  • Network access via TCP.
  • Full system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

Identifying the appropriate teams to address this vulnerability requires understanding your Oracle Coherence deployment. Typically, platform or middleware teams manage Coherence as a core service, while application owners are responsible for the applications that rely on it. The initial practical step is to locate all Coherence instances, assess their network exposure and business criticality, and then engage the accountable owner to plan remediation, potentially coordinating with Oracle for specific guidance.

  • Platform/Middleware teams own the issue.
  • Verify Coherence instance exposure and criticality.
  • Plan remediation with application owners.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a distributed data grid and caching layer used in enterprise environments. It serves as a middleware component that allows applications to store and manage data across multiple servers, helping to improve performance and scalability for backend systems.

What does this vulnerability mean for Oracle Coherence?

This vulnerability is a critical security flaw in the core component of Oracle Coherence. It allows an attacker to gain complete control over the system, meaning they could potentially access, change, or delete the data stored in the grid and disrupt its operations.

How does an attacker trigger CVE-2026-60221?

An attacker triggers this vulnerability by sending malicious requests over a TCP network connection. Crucially, the attacker does not need any user credentials or login rights to initiate this, but they must have direct network connectivity to the affected Coherence instance.

Is my Oracle Coherence deployment at risk?

According to Halo Surface Signal, this software is typically found in protected internal network segments, backend clusters, or middleware tiers rather than the public internet. If your instances are shielded behind firewalls and are not internet-facing, the likelihood of a remote attack is significantly lower.

What should I do to respond to this advisory?

First, create an inventory of all Oracle Coherence instances within your environment. Work with your platform or middleware teams to assess where these instances reside on your network and identify the business applications that depend on them. Once mapped, coordinate with the appropriate owners to plan for the vendor-supplied updates.

References