Oracle Coherence Component in Oracle Fusion Middleware Vulnerability
CVE-2026-60286
9.8CRITICAL
What is CVE-2026-60286?
A vulnerability in the Oracle Coherence component of Oracle Fusion Middleware poses a significant risk to users of versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. This flaw allows an unauthenticated attacker with network access via HTTP to exploit the system, resulting in a potential takeover of Oracle Coherence. Given its ease of exploitation, it is crucial for organizations to address this vulnerability promptly to protect their systems.
Affected Version(s)
Oracle Coherence 12.2.1.4.0
Oracle Coherence 14.1.1.0.0
Oracle Coherence 14.1.2.0.0