External risk intelligence

Oracle Coherence Network Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60287

Oracle Coherence is a data grid solution typically deployed within internal application tiers, back-end clusters, or private network segments to support middleware services. While it requires network access, it is generally not designed to be directly exposed to the public internet, though it may be reachable in misconfigured or specific architectural deployments.

Missing Authentication

Oracle Coherence

12.2.1.4.014.1.1.0.014.1.2.0.015.1.1.0.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component of Oracle Fusion Middleware. This issue is easily exploitable by an unauthenticated attacker with network access, potentially leading to a complete takeover of the Coherence system and impacting confidentiality, integrity, and availability. The main concern is confirming relevance and exposure given the product's typical deployment in internal environments.

  • Unauthenticated attackers can fully control Coherence.
  • Significant impact on systems where Coherence is deployed.
  • Confirm if your Oracle Coherence is exposed.

Attack Path

How an attacker could exploit the issue

An attacker can compromise Oracle Coherence by sending network requests to the vulnerable component. This requires no prior authentication or special user interaction, making it easy to exploit remotely. Successful attacks can lead to a complete takeover of the affected system.

  • Attacker needs network access.
  • Attacker exploits the Core component.
  • Risk of system takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access could compromise Oracle Coherence, potentially leading to a complete takeover of the system when supported by the advisory. This vulnerability impacts confidentiality, integrity, and availability.

  • Oracle Coherence system.
  • Network access via TCP.
  • Takeover of Oracle Coherence.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle Coherence component of Oracle Fusion Middleware is affected by this vulnerability, indicating that application owners and infrastructure or platform teams are likely responsible for remediation. The first practical step is to identify all instances of Oracle Coherence, determine their business criticality and network reachability, and then confirm the accountable owner. Once ownership is established, a risk-based remediation plan can be developed, potentially involving vendor coordination or temporary risk reduction measures.

  • Application or Platform teams own the issue.
  • Verify Coherence instances and criticality first.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid solution that provides distributed caching and data management. It is a core component within the Oracle Fusion Middleware stack, commonly used by enterprises to handle large volumes of data and stateful application information across clusters of servers, ensuring that data remains highly available and scalable for backend services.

How does CVE-2026-60287 impact system security?

This vulnerability represents a critical security flaw that allows unauthorized parties to gain complete control over the Coherence component. It is classified as a high-severity issue because it can compromise the core data grid, potentially allowing an attacker to read, modify, or delete the information stored within the system, as well as disrupting its operational availability.

Do I need special access to trigger this vulnerability?

No, the vulnerability does not require any prior authentication or user interaction. An attacker only needs network-level access to the Oracle Coherence component via TCP to initiate an exploit. If your instance is isolated and not reachable over a network, it cannot be targeted by this specific flaw.

Is my Oracle Coherence instance at risk?

According to Halo Surface Signal, this software is typically deployed within internal tiers or private network segments. It is not generally intended for direct public internet access. Your risk level depends on whether your network architecture allows unauthorized connections to the component, so confirm if your specific deployment is accessible from outside your trusted environment.

What should I do first to manage this threat?

Start by identifying all deployed instances of Oracle Coherence across your infrastructure. Once you have a complete inventory, determine which instances are business-critical and analyze their network reachability. Coordinate with your application or platform teams to establish ownership and develop a remediation plan, which may include applying vendor-supplied updates or adjusting network access controls.

References