External risk intelligence

Oracle Coherence Core Vulnerability Allows Network Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60227

Oracle Coherence is a data grid solution typically deployed within internal application tiers or back-end infrastructure to support other services. While network-reachable, it is not designed to be a public-facing edge service, gateway, or internet-accessible portal in standard architecture.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in Oracle Coherence, a component within Oracle Fusion Middleware. This issue allows an unauthenticated attacker with network access to potentially take over the Oracle Coherence system, impacting confidentiality, integrity, and availability. Given its critical CVSS score of 9.8, understanding its relevance to our environment is important.

  • Unauthenticated attackers can fully control Oracle Coherence.
  • Critical flaw affects a core data management component.
  • Confirm Oracle Coherence relevance and exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending network requests over TCP to a vulnerable Oracle Coherence instance. This could allow them to gain complete control over the Coherence system, potentially leading to a full takeover of the affected component.

  • Network access via TCP required.
  • Core component is the trigger point.
  • Risk of full system takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could impact Oracle Coherence, potentially leading to a complete takeover of the system. An unauthenticated attacker with network access could exploit this to gain control, affecting the confidentiality, integrity, and availability of the Coherence service and any data it manages.

  • Oracle Coherence system.
  • Network access via TCP.
  • Complete takeover of Coherence.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Oracle Coherence could lead to a full takeover of the product, impacting data confidentiality, integrity, and availability. Teams likely responsible for addressing this include application owners who rely on Coherence for their services, platform teams managing the Fusion Middleware infrastructure, and potentially network and security teams for exposure assessment. The first practical step is to identify all Coherence instances, confirm their network reachability and business criticality, and then assign an accountable owner for remediation planning.

  • Application and platform owners should address.
  • Verify Coherence instance exposure and criticality.
  • Plan remediation based on risk and impact.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a data grid solution within the Oracle Fusion Middleware suite. It acts as an in-memory storage and processing layer that allows applications to cache and manage large volumes of data across multiple servers. It is commonly used as backend infrastructure to improve the performance and scalability of enterprise applications.

What does CVE-2026-60227 mean for system security?

This vulnerability is a critical security flaw in the core component of Oracle Coherence. It allows an attacker to compromise the entire system without needing a username or password. Because it impacts confidentiality, integrity, and availability, a successful exploit could grant an unauthorized person complete control over the data grid and the information it processes.

How can an attacker trigger this vulnerability?

An attacker triggers this flaw by sending malicious requests over a TCP network connection directly to an affected Oracle Coherence instance. It does not require any specific user interaction, such as clicking a link or logging in. However, the attack only succeeds if the target system is reachable via the network; it cannot be triggered by local actions alone.

Is my environment at risk from this vulnerability?

Per Halo Surface Signal, Oracle Coherence is typically used in internal backend tiers rather than as an internet-facing gateway. While you should verify your specific architecture, systems that are not accessible from public networks are inherently shielded from the external, unauthenticated network access required to exploit this flaw.

What are the first steps to address this issue?

Begin by identifying all Oracle Coherence instances currently running in your environment. Confirm which versions are in use and determine their network reachability to understand your actual risk. Once identified, coordinate with the platform or application owners responsible for those systems to prioritize and plan for necessary software updates.

References