External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60228

Oracle Coherence is a data grid solution typically deployed in backend or internal infrastructure to support application clustering and caching. While it utilizes network-accessible TCP protocols, it is generally designed to operate within internal or protected environments rather than being directly exposed to the public internet.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component of Oracle Fusion Middleware. This issue allows an unauthenticated attacker with network access to potentially gain complete control over the Coherence system, impacting confidentiality, integrity, and availability. The main concern is confirming relevance and exposure within your environment.

  • Unauthenticated attackers can gain full control.
  • Affects Oracle Coherence, a backend data solution.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could compromise Oracle Coherence by leveraging its network accessibility through TCP. This vulnerability allows an unauthenticated individual with network access to gain complete control over the affected Coherence system.

  • Requires network access.
  • Exploited via TCP.
  • Leads to full system takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to take control of Oracle Coherence. This means sensitive system data and potentially service behavior could be affected when the product is accessible over a network.

  • System data and service behavior at risk.
  • Attacker gains network access via TCP.
  • Complete takeover of Oracle Coherence.

Operational Fix

Recommended remediation, mitigation, and detection steps

In a real-world scenario, Oracle Coherence vulnerabilities are typically owned by the platform or infrastructure teams responsible for the Fusion Middleware deployment. The initial step involves identifying all instances of Oracle Coherence, assessing their network accessibility and business criticality, and then pinpointing the specific application or service owners accountable for each instance to plan remediation.

  • Platform/Infrastructure teams own remediation.
  • Verify instance accessibility and criticality.
  • Plan coordinated remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution used to manage, cache, and distribute data across clustered servers. It functions as a foundational component within Oracle Fusion Middleware, helping large-scale applications handle high volumes of traffic and maintain data consistency across distributed environments.

How does CVE-2026-60228 affect Oracle Coherence?

This vulnerability represents a critical security weakness that allows an unauthorized user to gain complete control over the Coherence system. Because it affects the core functionality of the software, an attacker who successfully triggers it can manipulate the system's data, interfere with its operational behavior, and fully compromise the instance without needing any prior credentials.

Do I need to be authenticated to trigger this flaw?

No, authentication is not required. The vulnerability is triggered when an attacker has network access to the target system via TCP. Importantly, this issue does not require the attacker to have user privileges or existing access to the application; any network path that allows direct communication with the vulnerable component is sufficient for an attacker to attempt the exploit.

How do I know if my environment is at risk?

Halo Surface Signal notes that while Oracle Coherence uses network-accessible TCP protocols, it is usually deployed in backend or internal infrastructure rather than directly on the public internet. You are most at risk if your instances are not properly isolated within protected segments or if they are inadvertently reachable from untrusted network zones, which could broaden the potential reach for an attacker.

What should I do first to address this vulnerability?

Start by identifying all instances of Oracle Coherence running in your infrastructure. Coordinate with the platform or infrastructure teams who manage your Fusion Middleware to verify exactly where these instances are located and confirm whether they are accessible over the network. Once mapped, assess the criticality of these services to prioritize your response efforts and plan the necessary software updates.

References