CVE-2026-60223: High severity Oracle Oracle Coherence (Oracle Fusion Middleware) vulnerability
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Because unauthorized unauthenticated network attackers can cause a hang or frequently repeatable crash (complete DoS) of Oracle Coherence, restrict network access to Oracle Coherence over TCP to only trusted sources (e.g., via firewall/ACL) until the affected version is remediated.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60223?
CVE-2026-60223 has a high severity rating of 7.5.
How do I fix CVE-2026-60223?
To address CVE-2026-60223, you should apply the latest security patches provided by Oracle for the affected versions.
What products are affected by CVE-2026-60223?
CVE-2026-60223 affects Oracle Coherence in versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Who can exploit CVE-2026-60223?
CVE-2026-60223 can be exploited by unauthenticated attackers with network access via TCP.
What is the impact of CVE-2026-60223?
The impact of CVE-2026-60223 is the potential compromise of Oracle Coherence resulting in denial of service.