External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60224

Oracle Coherence is a data grid solution typically deployed within internal application tiers to support backend infrastructure. While it requires network access and may be reachable in some environments, it is not standard design for it to be directly exposed to the public internet, usually sitting behind application servers or internal firewalls.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue, easily exploitable by unauthenticated attackers over the network, could lead to a complete takeover of the Coherence system, impacting confidentiality, integrity, and availability with a severe CVSS score of 9.8. The main concern is confirming relevance and exposure, as Oracle Coherence is typically an internal technology.

  • An unauthenticated attacker can take over Oracle Coherence.
  • This affects a critical internal data management technology.
  • Confirm relevance and exposure of this Oracle component.

Attack Path

How an attacker could exploit the issue

An attacker can compromise Oracle Coherence by exploiting a vulnerability that allows unauthenticated network access. This vulnerability resides in the Core component of Oracle Coherence, a product within Oracle Fusion Middleware. Successful exploitation could lead to a complete takeover of the affected Oracle Coherence system.

  • Attacker needs network access.
  • Vulnerability is in the Core component.
  • Risk is complete system takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via TCP could potentially compromise Oracle Coherence, leading to a complete takeover of the system. This could affect the confidentiality, integrity, and availability of the data and services managed by Oracle Coherence.

  • Oracle Coherence system data.
  • Network access allows exposure.
  • Complete takeover of Oracle Coherence.

Operational Fix

Recommended remediation, mitigation, and detection steps

An unauthenticated network attacker can compromise Oracle Coherence, leading to a full takeover. Given Oracle Coherence's role in supporting backend infrastructure, platform or application owners are likely responsible for this component. The first practical step is to identify all instances of Oracle Coherence, confirm their network accessibility and business criticality, and then assign ownership for risk-based remediation planning.

  • Platform or application owners.
  • Confirm network reachability and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution that serves as a caching and data management layer. It is a core technology within Oracle Fusion Middleware, frequently used by enterprise applications to store and process data quickly across distributed systems to improve performance and scalability.

How does CVE-2026-60224 affect Oracle Coherence?

This vulnerability indicates a significant security weakness in the core component of Oracle Coherence. It allows an attacker to bypass authentication mechanisms entirely. Because of the nature of the flaw, a successful attack can result in a full system takeover, granting the attacker control over the data and services managed by the platform.

Do I need to be a logged-in user to trigger this vulnerability?

No. The vulnerability does not require any credentials, specific user interaction, or elevated privileges to execute. An attacker only needs network access via TCP to the affected service to initiate the attack. If the service is isolated from the network, the attack path is significantly disrupted.

Is my Oracle Coherence deployment at risk?

According to Halo Surface Signal, Oracle Coherence is typically designed for use in internal application tiers rather than being directly exposed to the public internet. While it is rarely meant to be internet-facing, you should confirm your specific architecture. If your instance is accessible via the broader network, it moves from a protected internal status to a more reachable target.

How should I respond to this Oracle Coherence vulnerability?

Begin by auditing your infrastructure to locate all instances of Oracle Coherence across your environment. Once identified, verify which instances have network exposure and assess their business criticality. Coordinate with the relevant application or platform owners to establish ownership, confirm their network reachability, and prioritize remediation planning based on that risk.

References