External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60236

Oracle Coherence is a data grid solution typically deployed in back-end infrastructure to support application clustering and caching. While it communicates over TCP and can be network-reachable, it is generally designed for internal communication between application components rather than as a public-facing service or edge gateway.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue is easily exploitable by attackers who can access it over the network, potentially leading to a complete takeover of the Oracle Coherence system. The high CVSS score of 9.8 indicates significant impacts on confidentiality, integrity, and availability. The main concern at this stage is to confirm if this technology is in use within our environment.

  • Unauthenticated network access can seize control.
  • Critical Oracle Coherence systems are at risk.
  • Confirm if Oracle Coherence is deployed.

Attack Path

How an attacker could exploit the issue

An attacker could target Oracle Coherence by sending malicious network traffic over TCP. Since no authentication is required, an unauthenticated attacker with network access can exploit this vulnerability to gain complete control of the Coherence system, potentially leading to a full takeover.

  • No authentication needed.
  • Network access via TCP.
  • Complete system takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via TCP could compromise Oracle Coherence, potentially leading to a full takeover of the system. This vulnerability impacts the confidentiality, integrity, and availability of the affected Oracle Coherence environments.

  • System data and service behavior at risk.
  • Exposure via network access over TCP.
  • Full takeover of Oracle Coherence.

Operational Fix

Recommended remediation, mitigation, and detection steps

Attackers can compromise Oracle Coherence through an easily exploitable vulnerability, leading to a complete takeover. Infrastructure, platform, or application teams are likely responsible for this Oracle Fusion Middleware component. The first practical step is to identify all Coherence deployments, confirm their network accessibility and business criticality, and then assign ownership for a risk-based remediation plan.

  • Infrastructure or Platform teams should own the issue.
  • Verify network reachability and business criticality first.
  • Plan remediation based on identified risk and ownership.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence and why is it used?

Oracle Coherence is a data grid solution found within Oracle Fusion Middleware. It is used by organizations to manage and cache data across clusters of servers, enabling applications to perform faster and scale efficiently. It acts as a back-end infrastructure component that handles high-speed data processing and distribution for complex enterprise software.

What does the CVE-2026-60236 vulnerability mean?

This vulnerability is a flaw in the core component of Oracle Coherence that allows an unauthorized user to gain full control of the system. Because it requires no login credentials, it is considered highly dangerous. In security terms, this is a critical weakness that lets an attacker bypass standard security measures to manipulate or access the underlying data grid directly.

How do attackers trigger this vulnerability?

An attacker triggers this issue by sending specially crafted network traffic over TCP to a target system running an affected version of Oracle Coherence. It is important to note that simply having the software installed is not enough; the attacker must have network connectivity to the specific service port. Internal system calls or local processes that do not traverse the network are not the primary path for this remote attack.

Is my Oracle Coherence instance at risk?

Halo Surface Signal notes that while Oracle Coherence is typically used for internal communication, it can be reachable over a network. You should prioritize assets that have TCP connectivity exposed to broader segments of your network. Even if the service is not directly on the public internet, any internal visibility that allows an attacker to send packets to the Coherence port increases the risk level.

What should I do first to address this?

Your first step is to locate all instances of Oracle Coherence within your environment. Once you have an inventory, verify which systems have network access over TCP and determine their business function. Do not assume all instances are isolated; identify who owns each deployment so that your infrastructure or platform teams can prepare for necessary security updates or configuration changes.

References