CVE-2026-60217: Critical severity Oracle Oracle Coherence (Oracle Fusion Middleware) vulnerability
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60217?
CVE-2026-60217 has a critical severity level of 10.
How do I fix CVE-2026-60217?
To address CVE-2026-60217, you should update to the latest supported version of Oracle Coherence.
What versions of Oracle Coherence are affected by CVE-2026-60217?
The affected versions of Oracle Coherence are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Who can exploit the vulnerability identified as CVE-2026-60217?
CVE-2026-60217 can be exploited by unauthenticated attackers with network access via TCP.
What is the potential impact of exploiting CVE-2026-60217?
Exploiting CVE-2026-60217 can lead to complete compromise of the Oracle Coherence product, including confidentiality, integrity, and availability breaches.