External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60280

Oracle Coherence is a data grid product typically deployed within internal application tiers to support backend services. While the vulnerability is reachable via HTTP/2, this component is not natively designed to be exposed directly to the public internet in standard deployments, though it may be accessible in specific, non-default architectural configurations.

Missing Authentication

Oracle Coherence

14.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component of Oracle Fusion Middleware. This issue is easily exploitable by attackers over the network and could lead to a complete takeover of the Coherence system, impacting data confidentiality, integrity, and availability. The primary concern is to determine if this technology is in use and assess potential exposure.

  • Attackers can seize control of Oracle Coherence.
  • Critical systems are at risk if Coherence is deployed.
  • Confirm relevance and any potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can leverage network access through HTTP/2 to reach Oracle Coherence and trigger a vulnerability in its Core component. Successful exploitation could lead to a complete takeover of the product.

  • No authentication required.
  • Network access via HTTP/2.
  • Full system takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to take control of Oracle Coherence when it is accessed via HTTP/2. Such an attack could lead to a complete compromise of the affected Coherence system.

  • Oracle Coherence system data.
  • Unauthenticated network access.
  • Complete takeover of Coherence.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given that Oracle Coherence is typically part of Oracle Fusion Middleware and used for data grid functionality within internal application tiers, application owners and infrastructure teams are likely responsible for addressing this vulnerability. The first practical step is to identify all instances of Oracle Coherence, determine their network accessibility, assess business criticality, and then confirm the accountable owner for remediation planning.

  • Identify accountable product/platform owners.
  • Verify network exposure and business criticality.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution that provides distributed caching and data processing capabilities. It is a core component of Oracle Fusion Middleware, frequently used by large-scale applications to manage high volumes of data, improve system responsiveness, and ensure data availability across clustered environments.

What does CVE-2026-60280 mean for the software?

This CVE identifies a critical flaw in the Core component of Oracle Coherence. It allows an attacker to gain unauthorized control over the software. Because it involves a complete takeover of the system's capabilities, it poses a severe risk to the confidentiality, integrity, and availability of any data managed by the affected Coherence instance.

How is this vulnerability triggered?

The vulnerability is triggered when an attacker sends specifically crafted requests over the network using the HTTP/2 protocol. It does not require any authentication, meaning the attacker does not need valid user credentials to initiate the attack. Interactions that do not utilize HTTP/2 or are restricted from network access are not subject to this specific trigger path.

Is my Oracle Coherence instance at risk?

According to Halo Surface Signal, Oracle Coherence is typically deployed within internal application tiers, making it less likely to be directly reachable from the public internet. However, if your specific architectural configuration allows for direct HTTP/2 network access to the Coherence component, your instance is at a significantly higher risk of exploitation.

What should I do if I use Oracle Coherence?

The immediate priority is to locate all instances of Oracle Coherence within your environment. Once identified, evaluate the network architecture to determine if the Coherence component is reachable via HTTP/2 and assess its business criticality. Use this information to coordinate with the responsible platform or infrastructure owners to initiate remediation planning.

References