CVE-2026-60298: Critical severity Oracle Oracle Coherence vulnerability
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60298?
The severity of CVE-2026-60298 is rated as critical with a score of 9.8.
How do I fix CVE-2026-60298?
To fix CVE-2026-60298, you should upgrade to the latest patched version of Oracle Coherence available for your environment.
Who is affected by CVE-2026-60298?
CVE-2026-60298 affects users of Oracle Coherence in versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
What type of attack can exploit CVE-2026-60298?
CVE-2026-60298 can be exploited by an unauthenticated attacker with network access via TCP.
What component of Oracle Fusion Middleware is impacted by CVE-2026-60298?
CVE-2026-60298 impacts the Core component of the Oracle Coherence product within Oracle Fusion Middleware.