External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60285

Oracle Coherence is a distributed caching and data grid solution typically deployed within internal application tiers to support backend services. While it uses network protocols for communication, it is not designed to be directly exposed to the public internet in standard deployment patterns, typically residing behind firewalls or within private data center networks.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This CVE identifies a critical vulnerability in Oracle Coherence, a component within Oracle Fusion Middleware, that could allow an unauthenticated attacker to completely take over the system over the network. The significant CVSS score of 9.8 indicates a high potential for Confidentiality, Integrity, and Availability impacts.

  • Unauthenticated remote attackers can fully compromise Oracle Coherence.
  • Critical vulnerability impacts core middleware product, potentially affecting operations.
  • Confirm relevance and exposure to Oracle Coherence systems.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker with network access can target Oracle Coherence's core component. By sending specially crafted network requests, an attacker could exploit this vulnerability to gain complete control over the Oracle Coherence system.

  • No authentication required.
  • Network access via TCP.
  • Takeover of Oracle Coherence.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access over TCP could potentially compromise Oracle Coherence, leading to a full takeover of the system. This could affect the confidentiality, integrity, and availability of the data managed by Oracle Coherence.

  • System takeover of Oracle Coherence.
  • Unauthenticated network access via TCP.
  • Complete compromise of service.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given that Oracle Coherence is a component of Oracle Fusion Middleware and commonly deployed as a backend service, application owners and infrastructure teams are likely responsible for addressing this vulnerability. The initial step should be to locate all instances of Oracle Coherence, assess their network accessibility and business criticality, and then identify the specific teams or individuals accountable for remediation planning and execution.

  • Application and infrastructure teams own the issue.
  • Verify Oracle Coherence network exposure and criticality.
  • Plan vendor coordination and scheduled maintenance.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid and caching software used by enterprises to store, manage, and process massive amounts of data across multiple servers. It acts as a high-performance backend layer within Oracle Fusion Middleware, helping applications scale by keeping frequently accessed data readily available in memory rather than relying solely on slower traditional databases.

How does CVE-2026-60285 affect the system?

This vulnerability represents a significant security weakness in the Core component of Oracle Coherence. It allows an unauthorized actor to send malicious network traffic to the software and potentially gain full control over the system. Because it affects the core functionality, a successful compromise could impact the confidentiality of the data stored, the integrity of the information, and the overall availability of the services relying on the cache.

Do I need authentication for this to happen?

No, this vulnerability does not require authentication. An attacker does not need valid login credentials to target the system. The flaw is triggered by sending specially crafted network requests directly to the Oracle Coherence service over TCP. Note that requests from unauthorized users or systems with the necessary network reach can trigger this, regardless of their privilege level.

Is my Oracle Coherence instance at risk?

Risk depends heavily on your network architecture. According to Halo Surface Signal, Oracle Coherence is typically deployed within protected internal tiers to support backend operations and is generally not designed to be reachable from the public internet. Systems residing behind robust firewalls or within isolated private data centers have a significantly reduced likelihood of being targeted by external threats compared to those accidentally exposed.

What should I do to secure my environment?

Begin by identifying every server running Oracle Coherence in your environment to understand your footprint. Once mapped, confirm whether these instances are accessible over the network as intended or if they have unintended exposure. Collaborate with your infrastructure and application teams to verify the specific version you are running and prepare for maintenance or vendor-provided updates to mitigate the risk.

References