CVE-2026-60286: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Security readout for executives and security teams
Plain-English summary
CVE-2026-60286 is a critical Oracle Coherence vulnerability that can let an unauthenticated network attacker take over affected Coherence deployments over HTTP. The vendor rates it CVSS 9.8 with full confidentiality, integrity, and availability impact.
Executive priority
Treat this as an immediate patch-and-exposure-reduction item for any affected Oracle Coherence environment, especially where HTTP access crosses trust boundaries.
Technical view
Oracle reports an easily exploitable vulnerability in Oracle Coherence Core affecting versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Attack vector is network via HTTP, with no privileges or user interaction required. Successful exploitation can result in Oracle Coherence takeover.
Likely exposure
Organizations running the listed Oracle Coherence versions with HTTP-accessible Coherence services are the primary exposure group. Internet-facing, partner-accessible, or broadly internal HTTP paths materially increase risk.
Exploitation context
The provided bundle does not show CISA KEV listing or cite active exploitation. However, the vulnerability is unauthenticated, network-reachable, low complexity, and takeover-impacting, making it urgent even without confirmed exploitation evidence.
Researcher notes
The source bundle provides severity, affected versions, vector, and takeover impact, but no CWE, proof-of-concept status, fixed-version details, or named workaround. Avoid inferring exploit mechanics from the HTTP vector alone.
Mitigation direction
Review Oracle's July 2026 Critical Patch Update guidance for CVE-2026-60286.
Prioritize vendor-supported remediation for affected Oracle Coherence versions.
Restrict HTTP access to Coherence services to trusted networks only.
Monitor Oracle advisories for fixed versions, workarounds, or follow-up guidance.
Increase logging and alerting around unexpected Coherence HTTP access.
Validation and detection
Inventory Oracle Coherence deployments and record exact versions.
Confirm whether versions match 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0.
Map HTTP exposure paths for Coherence across internet, partner, and internal networks.
Verify remediation status against Oracle's advisory, not assumptions.
Check CISA KEV and vendor updates for exploitation status changes.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2026-60286 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
2Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.