External risk intelligence

Oracle Coherence Core HTTP/2 Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60264

Oracle Coherence is a data grid and caching layer typically deployed within internal application architectures to support middleware services. While the vulnerability is reachable via HTTP/2, this component is generally not intended to be exposed directly to the public internet, making public exposure possible in some configurations but not a standard deployment pattern.

Information Disclosure

Oracle Coherence

14.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue could allow an unauthenticated attacker with network access to gain complete control of the affected Coherence instances, potentially impacting data integrity and availability. The main concern is confirming relevance and exposure within your environment.

  • Unauthenticated attackers can take over Oracle Coherence.
  • Understand if Oracle Coherence is exposed externally.
  • Confirm relevance and potential exposure in your environment.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker with network access could exploit a vulnerability in Oracle Coherence by sending specially crafted requests over HTTP/2. This could allow them to gain complete control over the affected Oracle Coherence system.

  • No authentication required.
  • Triggered via network access.
  • Full system takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access via HTTP/2 to compromise Oracle Coherence, potentially leading to a full takeover of the component. This means an attacker could gain complete control over the Coherence system, affecting its confidentiality, integrity, and availability.

  • Oracle Coherence system data.
  • Network access via HTTP/2.
  • Complete takeover of Oracle Coherence.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world responsibility for addressing this critical vulnerability likely falls to the Oracle Coherence administrators and the middleware or application platform teams who manage its deployment and integration. The first practical step is to identify all instances of Oracle Coherence across the environment, confirm network reachability and business criticality, and then engage the accountable team to plan remediation, which may involve coordination with Oracle and potentially vendor management for support.

  • Middleware or platform team owns the issue.
  • Verify network exposure and business impact.
  • Plan coordinated remediation with Oracle.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution used to provide fast data access and caching for high-performance applications. It acts as a middleware layer that clusters servers together to share data, allowing applications to handle massive volumes of information efficiently. It is frequently deployed within enterprise architectures to support large-scale, distributed middleware services that require low-latency data availability.

What does this CVE-2026-60264 vulnerability mean?

This vulnerability is a security flaw in the Oracle Coherence Core component. It represents a critical weakness that allows an attacker to bypass security controls entirely. By sending specific requests, an unauthorized user can gain complete control over the system, potentially accessing sensitive information, altering stored data, or crashing the service, resulting in a full system takeover.

How is the vulnerability in Oracle Coherence triggered?

The vulnerability is triggered when an attacker sends specifically crafted requests to an affected system using the HTTP/2 protocol. It does not require any prior authentication or special user permissions to execute. Notably, the attack cannot be triggered through non-networked local channels; it specifically relies on the ability to communicate with the service over a network connection that supports HTTP/2.

Do I need to worry if my Oracle Coherence instance is internal?

According to Halo Surface Signal, Oracle Coherence is typically intended for internal use within application architectures. While this makes it less likely to be directly reachable by the public internet, it is still possible for instances to be exposed through misconfiguration. You should prioritize checking if your deployment is reachable from outside your protected network, as internet-facing instances face the highest risk.

What should I do first to address this threat?

Begin by auditing your infrastructure to create a complete inventory of all Oracle Coherence instances currently running in your environment. Once identified, verify which instances are reachable over a network and determine their business criticality. Coordinate with your middleware or platform administration teams to plan and apply the necessary security updates provided by Oracle to secure the affected systems.

References