External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60274

Oracle Coherence is a distributed data grid used for application caching and processing. While it relies on TCP network access, it is typically deployed within internal application tiers or backend clusters to support middleware services. While it can be exposed in specific complex architectures, it is not a traditional internet-facing gateway or web service by default.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component of Oracle Fusion Middleware. This issue, which can be exploited by unauthenticated attackers over the network, could allow for a complete takeover of the Coherence system, impacting confidentiality, integrity, and availability. The primary concern at this stage is to confirm if this specific technology is in use within your environment.

  • Unauthenticated network access compromises Coherence.
  • Confirms if your Oracle Coherence is affected.
  • Understand potential system takeover risk.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by sending specially crafted network traffic to an exposed Oracle Coherence instance. This could allow them to take complete control of the affected Oracle Coherence system.

  • No authentication required.
  • Network access via TCP.
  • Full system takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access could compromise Oracle Coherence, potentially leading to a full takeover of the system. This vulnerability could impact the confidentiality, integrity, and availability of the Oracle Coherence service.

  • Oracle Coherence service.
  • Unauthenticated network access.
  • Complete system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given Oracle Coherence is a middleware component, platform or infrastructure teams are likely responsible for its management and security. The first practical step is to identify all Oracle Coherence deployments, determine their network accessibility and business criticality, and then locate the accountable owner to plan remediation based on risk.

  • Platform/Infrastructure teams own the issue.
  • Verify network exposure and business criticality.
  • Plan risk-based remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a distributed data grid and a core component of Oracle Fusion Middleware. It serves as a middleware layer that manages and caches large volumes of data across server clusters to support application performance.

How is CVE-2026-60274 classified?

This vulnerability represents a critical security flaw in the Oracle Coherence Core component. It is an unauthenticated, network-based issue with a CVSS 3.1 base score of 9.8, indicating severe risks to data confidentiality, integrity, and availability.

How might an attacker access the system?

An attacker can attempt to trigger this vulnerability by sending specially crafted TCP network traffic to an Oracle Coherence instance. This path does not require authentication or user interaction to facilitate a potential system takeover.

Why is this relevant for security teams?

According to the Halo Surface Signal, Oracle Coherence is typically deployed in internal backend tiers. While it has a Possible exposure score of 3, teams should evaluate their architectures because specific complex setups may inadvertently expose the service.

What are the recommended first steps for remediation?

Platform and infrastructure teams should immediately identify all active Oracle Coherence deployments. Once identified, verify the network accessibility and business criticality of each instance to prioritize risk-based remediation actions.

References