CVE-2026-60280: Critical severity Oracle Oracle Coherence (Oracle Fusion Middleware) vulnerability
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60280?
The severity of CVE-2026-60280 is critical, with a CVSS score of 9.8.
How do I fix CVE-2026-60280?
To fix CVE-2026-60280, upgrade to the latest supported version of Oracle Coherence that is not affected.
Who is affected by CVE-2026-60280?
Users of affected Oracle Coherence versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are at risk from CVE-2026-60280.
What components are involved in CVE-2026-60280?
CVE-2026-60280 involves the Core component of the Oracle Coherence product within Oracle Fusion Middleware.
Can CVE-2026-60280 be exploited remotely?
Yes, CVE-2026-60280 can be easily exploited remotely by an unauthenticated attacker with network access via HTTP/2.