CVE-2026-60299: Critical severity Oracle Oracle Coherence vulnerability
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60299?
The severity of CVE-2026-60299 is critical with a CVSS score of 9.8.
How do I fix CVE-2026-60299?
To fix CVE-2026-60299, apply the latest security patches provided by Oracle for the affected versions of Oracle Coherence.
What products are affected by CVE-2026-60299?
CVE-2026-60299 affects Oracle Coherence versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Can CVE-2026-60299 be exploited remotely?
Yes, CVE-2026-60299 can be easily exploited by an unauthenticated attacker with network access via TCP.
What kind of impact can CVE-2026-60299 have on Oracle Coherence?
CVE-2026-60299 can result in high confidentiality, integrity, and availability impacts, allowing attackers to compromise Oracle Coherence.