External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60279

Oracle Coherence is a middleware component typically used for caching and data grid services within backend application architectures. While the vulnerability is reachable via HTTP and does not require authentication, these systems are generally deployed in internal network segments to support application tiers rather than being directly exposed to the public internet.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware that supports data caching and grid services. This issue could allow an attacker to gain complete control of the affected systems, impacting confidentiality, integrity, and availability. The primary concern is to confirm if this technology is in use within the organization to assess potential exposure.

  • Attackers can fully control affected Oracle systems.
  • This issue allows complete system compromise.
  • Verify if Oracle Coherence is deployed internally.

Attack Path

How an attacker could exploit the issue

An attacker could target Oracle Coherence, a component within Oracle Fusion Middleware, by sending specially crafted network requests over HTTP. Since this vulnerability does not require authentication and is accessible via the network, an attacker could potentially compromise the entire Oracle Coherence system. This could lead to a complete takeover, impacting confidentiality, integrity, and availability.

  • Unauthenticated network access is sufficient.
  • HTTP requests trigger the vulnerability.
  • Complete system takeover is possible.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via HTTP could compromise Oracle Coherence, potentially leading to a complete takeover of the system. This vulnerability impacts the confidentiality, integrity, and availability of Oracle Coherence.

  • Oracle Coherence system compromised.
  • Unauthenticated network access allows compromise.
  • Full system takeover is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Oracle Coherence, a component often managed by platform or application teams responsible for the Fusion Middleware stack. The first critical step is to locate all instances of Oracle Coherence, determine their network exposure, identify business criticality, and confirm the owning team to prioritize remediation efforts.

  • Platform or application teams own the issue.
  • Verify Oracle Coherence exposure and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a middleware product within the Oracle Fusion Middleware family. It functions as an in-memory data grid solution that provides distributed caching and data management services. Technical teams typically use it to improve application performance and scalability by storing frequently accessed data across a cluster of servers, serving as a back-end support layer for larger enterprise software architectures.

What does this CVE mean for Oracle Coherence security?

CVE-2026-60279 describes a high-severity flaw where the software fails to properly secure its communication channels. This weakness allows an unauthorized party to send malicious instructions to the system. Because the software does not correctly validate these inputs, it can lead to a full system compromise, granting an attacker complete control over the affected Oracle Coherence instance.

How is the vulnerability triggered?

An attacker triggers this flaw by sending specially crafted HTTP requests to the targeted Oracle Coherence component. No authentication or login is required to initiate this process. Importantly, simply having the software installed is not enough to be compromised; the system must be reachable over the network via HTTP for these requests to reach the vulnerable component.

Do I need to worry if my systems are internal?

According to Halo Surface Signal, Oracle Coherence is frequently deployed within internal network segments to support backend application tiers rather than being directly exposed to the public internet. While this internal positioning provides a layer of isolation, you should still evaluate your specific environment, as any device with network access to the internal segment could potentially reach the service.

How should I respond to this vulnerability?

Your first step is to perform an inventory to identify all instances of Oracle Coherence running in your environment. Once identified, work with the platform or application teams responsible for the Fusion Middleware stack to determine the network accessibility and business criticality of each instance. This data will allow you to prioritize remediation efforts effectively for the most exposed or vital systems.

References