criticalZero-Day

Oracle Coherence Unauthenticated Remote Takeover Vulnerability

First seen Jul 24, 2026 · Updated Jul 24, 2026 · CVSS 9.8

oraclecoherencerceunauthenticatedmiddlewarecritical-infrastructureagent-relevant

CVE-2026-60296 is a critical, easily exploitable vulnerability in Oracle Coherence (Oracle Fusion Middleware) that allows an unauthenticated attacker with network access to fully compromise the affected server over TCP. With a CVSS score of 9.8 and no authentication or user interaction required, this flaw poses severe risk to any organization running affected Coherence versions, including those used as caching/data grid layers behind enterprise and AI-driven applications.

Technical Analysis

The vulnerability resides in the Core component of Oracle Coherence and is remotely exploitable via TCP without authentication (AV:N/AC:L/PR:N/UI:N), resulting in full compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, indicating the flaw likely exists in a long-lived core protocol handler or serialization/deserialization routine common across major releases. Given the low attack complexity, mass exploitation via internet-facing Coherence clusters or exposed management ports is plausible once technical details or a PoC surface. Organizations that use Oracle Coherence as a distributed caching or in-memory data grid layer for backend services—including those supporting RAG pipelines, vector store caches, or session/state management for AI agent orchestration—could see agent credentials, cached embeddings, or session tokens exposed or manipulated if the underlying Coherence cluster is compromised, and a takeover could allow lateral movement into systems hosting agent frameworks or API keys.

Affected Systems

Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 within Oracle Fusion Middleware, specifically the Core component; any Coherence cluster nodes exposed to network access (internal or internet-facing TCP endpoints).

Indicators of Compromise

  • No public IOCs available at this time (no known hashes, IPs, or domains associated with active exploitation as of publication)

Remediation Steps

  1. 1

    Apply Oracle Critical Patch Update

    Immediately apply the official Oracle CPU patch addressing CVE-2026-60296 for all affected Coherence versions.

  2. 2

    Restrict network exposure

    Ensure Coherence cluster communication ports (TCP) are not exposed to untrusted networks or the public internet; enforce firewall rules and network segmentation.

  3. 3

    Enable Coherence security features

    Configure Coherence cluster authentication, TLS for cluster communication, and access control lists to reduce unauthenticated attack surface.

  4. 4

    Monitor for exploitation indicators

    Review logs for anomalous unauthenticated connections to Coherence TCP endpoints and unexpected process execution on hosts running Coherence.

  5. 5

    Audit downstream systems

    If Coherence supports caching or session management for AI agent pipelines or API-key-dependent services, rotate exposed credentials and audit for unauthorized access post-patch.

CVE / Advisory IDs

CVE-2026-60296

Industries Most Exposed

financial servicestechnologytelecommunicationshealthcaregovernmentretailmanufacturing

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.