CVE-2026-60210: Critical severity Oracle Oracle Coherence (Oracle Fusion Middleware) vulnerability
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60210?
The severity of CVE-2026-60210 is rated as critical with a score of 9.8.
How do I fix CVE-2026-60210?
To fix CVE-2026-60210, upgrade to the latest version of Oracle Coherence that addresses this vulnerability.
What versions are affected by CVE-2026-60210?
The affected versions of Oracle Coherence are 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Who is at risk from CVE-2026-60210?
Unauthenticated attackers with network access via TCP are at risk of exploiting CVE-2026-60210.
What impact does CVE-2026-60210 have on Oracle Coherence?
CVE-2026-60210 allows an attacker to compromise Oracle Coherence, potentially compromising confidentiality, integrity, and availability.