External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60288

Oracle Coherence is a data grid and caching layer typically deployed within internal application tiers to support backend services. While network-accessible and theoretically reachable if misconfigured or exposed through a gateway, it is not designed to be a public-facing internet service.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue is easily exploitable by an unauthenticated attacker over the network, potentially leading to a complete takeover of the Coherence system. The severity indicates significant impacts on confidentiality, integrity, and availability.

  • An attacker can fully control Oracle Coherence.
  • This affects core data and application services.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted network traffic to Oracle Coherence. This vulnerability affects the core component of the product, and since it is easily exploitable by an unauthenticated attacker with network access, a successful attack could lead to a complete takeover of the Oracle Coherence system.

  • No authentication required.
  • Network traffic triggers vulnerability.
  • Risk of system takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via TCP could compromise Oracle Coherence, potentially leading to a complete takeover of the product. This vulnerability impacts confidentiality, integrity, and availability due to its ease of exploitation and network-based attack vector.

  • Oracle Coherence product.
  • Network access via TCP.
  • Complete takeover of Oracle Coherence.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Oracle Coherence, an Oracle Fusion Middleware component, is likely to impact application owners and infrastructure teams responsible for its deployment and maintenance. The initial step should be to identify all instances of Oracle Coherence within the environment, determine their network exposure, assess their business criticality, and then locate the accountable system owner to plan a risk-based remediation strategy.

  • Application and infrastructure teams own remediation.
  • Verify Coherence instance reachability and criticality.
  • Plan maintenance windows for mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is an in-memory data grid and caching solution used by enterprise applications to store, manage, and process large amounts of data across multiple servers. As a core component of Oracle Fusion Middleware, it helps backend services perform faster by keeping frequently accessed information readily available in memory rather than constantly querying a database.

How should I describe the vulnerability in CVE-2026-60288?

This vulnerability is a critical security flaw in the core component of Oracle Coherence. It allows an attacker to send unauthorized network commands that the system will execute. Because the software fails to properly verify the identity of the person or system sending these requests, it can be forced to grant an attacker full control over the application's data and operations.

What triggers this security flaw?

An attacker triggers this issue by sending specially crafted TCP network traffic directly to the Oracle Coherence service. Crucially, the attacker does not need a username or password to initiate this process. If the service is not receiving network traffic, or if it is isolated from the network, the vulnerability cannot be triggered via this path.

Is my Oracle Coherence instance at risk?

According to Halo Surface Signal, Oracle Coherence is typically used in internal application tiers. It is not designed to be a public-facing service. Your risk is highest if your instances are misconfigured or routed through a gateway that makes them reachable from the internet. You should verify if your specific deployment is accessible beyond your internal network.

When should I take action to secure this?

You should start immediately by identifying all Oracle Coherence deployments within your environment. Once identified, evaluate their network reachability and business importance to prioritize them. Work with the responsible application or infrastructure owners to determine the appropriate maintenance window for applying the necessary updates from the vendor.

References