CVE-2026-60276: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Security readout for executives and security teams
Plain-English summary
Oracle reports a critical Oracle Coherence vulnerability that can let an unauthenticated network attacker compromise the service over HTTPS. Successful exploitation can result in takeover of Oracle Coherence, affecting confidentiality, integrity, and availability. The affected versions listed are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Executive priority
Treat this as urgent for any business-critical Oracle Coherence deployment. The issue is unauthenticated, network-reachable, and rated critical with potential service takeover, but current evidence in the bundle does not confirm active exploitation.
Technical view
CVE-2026-60276 affects Oracle Coherence Core in Oracle Fusion Middleware. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, scoring 9.8. The source bundle does not identify a CWE, root cause, proof of concept, or detailed attack primitive beyond unauthenticated HTTPS network access and potential takeover.
Likely exposure
Organizations running Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0 are potentially exposed, especially where HTTPS access is reachable from untrusted networks.
Exploitation context
The provided sources describe the issue as easily exploitable without authentication or user interaction via HTTPS. The CVE is not marked KEV in the bundle, and no cited source here confirms active exploitation.
Researcher notes
The public details are limited. Do not assume a specific bug class or exploit path from the available sources. Focus research on affected-version confirmation, HTTPS exposure, advisory tracking, and safe detection of anomalous access patterns.
Mitigation direction
Check Oracle's July 2026 advisory for official remediation guidance.
Prioritize patch planning for all listed Oracle Coherence versions.
Restrict HTTPS access to trusted network paths until remediation is complete.
Increase monitoring for unusual Oracle Coherence access or takeover indicators.
Validation and detection
Inventory all Oracle Coherence deployments and versions.
Identify whether Coherence HTTPS endpoints are reachable from untrusted networks.
Confirm whether Oracle July 2026 CPU guidance has been applied.
Document remaining exposed instances and compensating access controls.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2026-60276 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
2Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.