CVE-2026-60251: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Security readout for executives and security teams
Plain-English summary
Oracle Coherence has a critical network-reachable flaw. An unauthenticated attacker with TCP access could compromise the Coherence service and potentially take it over. For organizations using affected versions, this is a high-urgency infrastructure risk because confidentiality, integrity, and availability are all rated high impact.
Executive priority
Treat this as an immediate patch-and-exposure-reduction item for any affected Coherence deployment. The business concern is possible takeover of a middleware component that may support critical applications or cached data flows.
Technical view
CVE-2026-60251 affects Oracle Coherence Core versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The CVSS 3.1 score is 9.8, with network attack vector, low complexity, no privileges, and no user interaction required. Successful exploitation can result in takeover of Oracle Coherence.
Likely exposure
Exposure is likely where affected Oracle Coherence versions are running and reachable over TCP. Systems with broad internal access, partner access, or internet-adjacent network paths should be prioritized. The source bundle does not provide CPEs or deployment-specific exposure details.
Exploitation context
The source bundle does not show CISA KEV listing, active exploitation, or public exploit availability. Risk is still urgent because the vulnerability is unauthenticated, network-accessible, low complexity, and can result in service takeover.
Researcher notes
No CWE, CPE list, exploit evidence, or detailed root cause is provided in the source bundle. Validation should stay focused on version matching, TCP reachability, and Oracle advisory mapping. Avoid assuming affected configurations beyond the listed versions and component.
Mitigation direction
Review Oracle's July 2026 advisory for the official fix guidance.
Patch affected Oracle Coherence versions as directed by Oracle.
Restrict TCP access to Coherence services to trusted networks only.
Prioritize internet-adjacent or broadly reachable Coherence deployments.
Monitor Oracle guidance for updated remediation details.
Validation and detection
Inventory Oracle Coherence deployments and confirm exact versions.
Identify TCP network paths to Coherence services.
Check whether listed affected versions are present.
Verify Oracle advisory applicability for each deployment.
Confirm patch status after remediation.
Review logs for unusual Coherence access attempts.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2026-60251 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
2Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.