External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60253

Oracle Coherence is a distributed caching and data grid solution typically deployed in back-end infrastructure rather than directly facing the public internet. While it requires network access, it is generally positioned behind firewalls or within internal service tiers, making direct public exposure uncommon in standard deployments despite its potential reachability via TCP.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware that handles distributed caching and data grids. This issue is easily exploitable by unauthenticated attackers over the network, potentially leading to a complete takeover of the Coherence system and impacting confidentiality, integrity, and availability. While the system requires network access, its typical deployment within internal infrastructure means direct public exposure is uncommon, making the primary concern confirming its relevance and exposure within our environment.

  • Unauthenticated attackers can take over Coherence.
  • Critical system takeover impacts data and operations.
  • Confirm relevance and exposure within our environment.

Attack Path

How an attacker could exploit the issue

An attacker could begin by sending network requests to an exposed Oracle Coherence service. Since no authentication is required, an attacker can directly interact with the Core component of Oracle Coherence, potentially leading to a complete takeover of the service.

  • Network access required.
  • Unauthenticated TCP requests.
  • Takeover of Oracle Coherence.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via TCP could compromise Oracle Coherence, potentially leading to a complete takeover of the system. This could impact the confidentiality, integrity, and availability of the data and services managed by Oracle Coherence.

  • Oracle Coherence system and data.
  • Network access to an unauthenticated attacker.
  • Complete takeover of the Oracle Coherence system.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given this vulnerability in Oracle Coherence, ownership likely falls to the platform or infrastructure teams responsible for managing Oracle Fusion Middleware deployments. The immediate first step is to identify all instances of Oracle Coherence within the environment, confirm their network accessibility and business criticality, and then assign an accountable owner for remediation planning based on the assessed risk.

  • Identify and assign the platform team owner.
  • Verify Oracle Coherence instance reachability.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a distributed caching and data grid component within Oracle Fusion Middleware. It is designed to store and manage large volumes of data across multiple servers, providing high-speed access for applications. It is frequently used in back-end infrastructures to support complex, data-intensive systems by keeping frequently used information readily available in memory.

What does this CVE-2026-60253 vulnerability mean?

This vulnerability represents a critical security weakness that allows an unauthenticated attacker to take control of the Oracle Coherence system. Because the system fails to require authentication, an attacker with network access can send requests to the Core component that result in a full system takeover, granting them the ability to impact the confidentiality, integrity, and availability of the managed data.

How can an attacker trigger this issue?

An attacker initiates this by sending specific, unauthenticated TCP requests directly to the Oracle Coherence service. The vulnerability relies on this network interaction; it is not triggered by user interaction or typical application usage. If a service instance cannot be reached via the network, the attack path is effectively blocked.

Is my Oracle Coherence instance at risk?

Halo Surface Signal notes that while this vulnerability is reachable via TCP, Oracle Coherence is typically deployed in internal service tiers behind firewalls. You should care if your instances are not properly isolated, as direct public internet exposure is uncommon in standard deployments but remains a critical risk factor if the service is accidentally exposed.

What should I do first to manage this risk?

Your first step is to perform an inventory to locate all running instances of Oracle Coherence in your environment. Once identified, verify the network reachability of each instance to determine if it is exposed to untrusted networks. Finally, designate an owner within your infrastructure or platform team to review the situation and plan for security updates.

References