Oracle Fusion Middleware Vulnerability in Oracle Coherence Product
CVE-2026-60306
9.8CRITICAL
What is CVE-2026-60306?
A vulnerability in the Oracle Coherence component of Oracle Fusion Middleware could allow an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful exploitation of this issue may enable a threat actor to take over the affected Oracle Coherence instances, significantly impacting confidentiality, integrity, and availability of the system. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Affected Version(s)
Oracle Coherence 12.2.1.4.0
Oracle Coherence 14.1.1.0.0
Oracle Coherence 14.1.2.0.0