
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-60306 is a critical unauthenticated remote code execution vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. It was disclosed on July 21, 2026, as part of Oracle's July 2026 Critical Patch Update. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (Oracle CPU Jul 2026).
The vulnerability resides in the Core component of Oracle Coherence and is exploitable by an unauthenticated attacker with network access via TCP, requiring no user interaction and no privileges. The attack complexity is low, making it trivially exploitable over a network. Oracle has not publicly disclosed the specific root cause or CWE classification, but the nature of the vulnerability — unauthenticated network access leading to full system takeover — is consistent with deserialization or remote code execution flaws historically associated with Oracle Coherence's T3/IIOP protocol handling. No public PoC or detailed technical write-up has been identified at this time (Oracle CPU Jul 2026).
Successful exploitation allows a remote, unauthenticated attacker to fully compromise the affected Oracle Coherence instance, with high impact to confidentiality, integrity, and availability. This effectively constitutes a complete takeover of the Coherence node, potentially enabling arbitrary code execution, data exfiltration, service disruption, and lateral movement within environments where Coherence is used as a distributed caching or data grid layer (Oracle CPU Jul 2026).
Oracle strongly recommends applying the patches released in the July 2026 Critical Patch Update for all affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) as soon as possible. As a temporary workaround, Oracle suggests blocking network protocols required by the attack (TCP access to Coherence ports) at the network perimeter to reduce exposure, though this may impact application functionality and is not a long-term solution. Organizations should ensure Coherence cluster ports are not exposed to untrusted networks and should prioritize patching given the critical severity and unauthenticated attack vector (Oracle CPU Jul 2026).
The vulnerability was noted by threat intelligence aggregators including VulDB and CVEFeed shortly after Oracle's July 2026 CPU disclosure. No significant researcher commentary, vendor statements beyond Oracle's advisory, or notable media coverage has been identified at this time (Oracle CPU Jul 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."