External risk intelligence

Oracle Coherence Core Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60306

Oracle Coherence is a distributed data grid used primarily for backend application caching and data management within internal enterprise environments. While it uses network protocols, it is typically deployed deep within an application stack and is not intended to be exposed directly to the public internet.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue could allow an unauthorized attacker to gain complete control of the system if successfully exploited remotely. The primary concern is to determine if this technology is in use and if it is exposed.

  • Unauthenticated attackers can take over Oracle Coherence.
  • Critical system control risk warrants attention.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending network requests to an exposed Oracle Coherence component. Because the vulnerability is easily exploitable and does not require authentication or user interaction, a remote attacker could gain unauthorized access and take complete control of the system, leading to significant data compromise and service disruption.

  • Entry Condition: Network access to the target system.
  • Trigger Point: Sending specially crafted network requests.
  • Resulting Risk: Complete takeover of the system.

Live Threat

Current exploitation, exposure, and threat context

A critical vulnerability in Oracle Coherence could allow an attacker to take complete control of the affected system. This could occur when the system is accessible over a network, potentially impacting the confidentiality, integrity, and availability of data managed by Oracle Coherence.

  • System data and service access.
  • Unauthenticated network access.
  • Full system takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given that Oracle Coherence is a component of Oracle Fusion Middleware, the platform or infrastructure teams responsible for managing Oracle products are likely to own this vulnerability. The first practical step is to identify all instances of Oracle Coherence within your environment, assess their network exposure and business criticality, and then determine the accountable owner for remediation.

  • Platform/Infrastructure teams own the issue.
  • Verify Oracle Coherence instances and exposure.
  • Plan risk-based remediation or vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

It is a distributed data grid used in Oracle Fusion Middleware to cache and manage large-scale data in memory across servers. It serves as a backend component that provides high-performance data access for enterprise applications.

How is CVE-2026-60306 classified?

This vulnerability is a critical flaw in the Core component of Oracle Coherence. It presents a maximum severity risk because it allows an unauthorized party to gain full control over the system, impacting the confidentiality, integrity, and availability of managed data.

What allows an attacker to trigger this vulnerability?

The issue is triggered by sending specially crafted network requests to the Oracle Coherence component. Because the flaw does not require user interaction or authentication, it can be exploited remotely by anyone with TCP network access to the target system.

Why is the actual risk level considered low by Halo Surface Signal?

Although the vulnerability is critical, the Halo Surface Signal indicates an Unlikely risk label. Oracle Coherence is typically deployed deep within internal enterprise stacks and is not designed to be exposed to the public internet.

How should teams respond to this vulnerability?

Teams should first identify all Oracle Coherence instances within their environment. Following identification, assess the network exposure and business criticality of each instance, then coordinate with the infrastructure owners to prioritize and plan the necessary remediation.

References