External risk intelligence

Oracle Coherence TCP Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60229

Oracle Coherence is a data grid and caching layer typically deployed within internal application tiers to support middleware and backend services. While it uses TCP for communication and could be reachable if misconfigured or improperly segmented, it is not designed to be a public-facing service, making internet exposure uncommon in standard, secure deployment patterns.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Oracle Coherence, a component of Oracle Fusion Middleware. The issue, if exploited, could allow an attacker to completely take over the Oracle Coherence system, impacting data confidentiality, integrity, and availability. The main concern is to confirm if this technology is in use within our environment and to what extent it might be exposed.

  • Unauthorized access could lead to full system compromise.
  • This technology is critical for certain application performance.
  • Confirm Oracle Coherence usage and exposure within our systems.

Attack Path

How an attacker could exploit the issue

An attacker can compromise Oracle Coherence by sending specially crafted network traffic over TCP to the vulnerable component. This attack does not require any prior authentication or user interaction, making it easily exploitable by anyone with network access. A successful attack can lead to the complete takeover of the Oracle Coherence system.

  • Unauthenticated network access via TCP.
  • Sending crafted network traffic to the Core component.
  • Complete takeover of Oracle Coherence.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access to compromise the Oracle Coherence data grid, potentially leading to a complete takeover of the system. This affects the confidentiality, integrity, and availability of the data and services managed by Coherence.

  • Oracle Coherence data and services.
  • Network access via TCP.
  • Complete system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

In a typical Oracle Fusion Middleware deployment, the Platform or Infrastructure teams are likely responsible for Oracle Coherence. Application owners should also be engaged to understand the business criticality and impact of any potential disruption. The first practical step is to identify all Coherence instances, confirm their network exposure and business impact, and then engage the accountable owners to plan remediation, considering maintenance windows and vendor coordination.

  • Platform/Infrastructure teams own the issue.
  • Verify network exposure and business criticality.
  • Plan coordinated remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a specialized software component within Oracle Fusion Middleware. It functions as an in-memory data grid and caching layer. Developers and architects use it to store, manage, and share application data across multiple servers, which helps speed up backend processing and improve the performance of complex enterprise systems.

What does CVE-2026-60229 mean for Oracle Coherence?

This CVE describes a critical flaw in the Core component of Oracle Coherence. It is a security weakness that allows an unauthorized person to send malicious network traffic to the system. Because the software does not properly validate this communication, an attacker could gain full control over the affected Coherence instance, potentially accessing or altering sensitive data managed by the grid.

How is the Oracle Coherence vulnerability triggered?

An attacker triggers this issue by sending specifically crafted data packets over a TCP connection to the Coherence component. It does not require a password or any prior interaction from a legitimate user. Simply having network connectivity to the target system is enough to initiate the attack. Normal, legitimate TCP traffic used for standard data grid operations does not trigger this vulnerability.

Is my Oracle Coherence instance at risk?

According to Halo Surface Signal, Oracle Coherence is typically used in internal tiers to support backend services and is not designed to be reachable from the internet. While your risk depends on your specific network configuration, instances that are accidentally exposed to public networks are at a much higher risk than those isolated within internal, secure network segments.

What should I do if I run Oracle Coherence?

Begin by inventorying your environment to locate all running instances of the affected versions. Once located, verify if any are reachable from outside your protected network. Collaborate with your infrastructure or platform teams to prioritize these systems, assess the business impact of potential maintenance, and prepare to apply the official security updates provided by the vendor.

References