External risk intelligence

Oracle Coherence Core Takeover Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60250

Oracle Coherence is a data grid and caching layer typically deployed in back-end environments rather than directly on the public internet. While the vulnerability is reachable over a network, it is generally found within internal application tiers or private infrastructure, making direct public internet exposure uncommon in standard deployments.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue, if exploited, could allow an unauthorized attacker to completely take over the Oracle Coherence system. The primary concern is to confirm if our environment utilizes the affected Oracle Coherence product and assess potential exposure.

  • Unauthenticated attackers can compromise Oracle Coherence.
  • Critical vulnerability could lead to full system takeover.
  • Confirm relevance and exposure within our Oracle Coherence usage.

Attack Path

How an attacker could exploit the issue

An attacker can compromise Oracle Coherence by sending malicious network traffic over TCP. This vulnerability does not require any prior authentication or user interaction, meaning an attacker can exploit it remotely. Successful exploitation allows an attacker to completely take over the affected Oracle Coherence system.

  • Unauthenticated network access required.
  • Triggered by network traffic over TCP.
  • Results in full system takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access could compromise Oracle Coherence, potentially leading to a complete takeover of the system. This is possible due to an easily exploitable vulnerability.

  • Oracle Coherence systems at risk.
  • Attacker gains network access via TCP.
  • Complete takeover of Oracle Coherence.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Oracle Coherence impacts core functionality and is easily exploitable by unauthenticated network access. Real-world ownership likely falls to the application or platform teams managing Oracle Fusion Middleware deployments, with coordination from infrastructure and security teams. The immediate first step is to identify all instances of Oracle Coherence, assess their network reachability and criticality, and confirm the accountable owner before planning remediation.

  • Application or platform teams own the issue.
  • Verify instance reachability and business criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution used by Oracle Fusion Middleware to provide high-speed caching and data storage. It allows applications to manage large volumes of data across distributed clusters, helping them scale and perform reliably in back-end environments.

What does CVE-2026-60250 mean?

CVE-2026-60250 represents a critical security weakness in the Core component of Oracle Coherence. It allows an unauthenticated attacker to send malicious network traffic to the system, potentially resulting in a full takeover where the attacker gains control over the software's functionality, data, and operations.

How is this vulnerability triggered?

An attacker triggers this issue by sending specifically crafted network traffic over TCP to a target Oracle Coherence instance. Importantly, this process does not require any prior authentication or user interaction; if an attacker has network access to reach the service, they can initiate the attack.

Who should care about this CVE?

Organizations running Oracle Coherence should investigate this risk. According to Halo Surface Signal, this software is typically deployed within private, internal application tiers rather than directly on the public internet. While direct public exposure is uncommon, internal networks or misconfigured segments that allow broad access still present a significant path for potential compromise.

What should I do if I use Oracle Coherence?

The first step is to perform a discovery process to locate all instances of Oracle Coherence within your infrastructure. Once identified, map out which systems are reachable over the network and determine the business criticality of those instances. Coordinate with the platform or application teams responsible for those specific deployments to prepare for remediation steps.

References