CVE-2026-60219: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
criticalvulnerability
security
Summary
Oracle Coherence, a data management product in Oracle Fusion Middleware, has a critical vulnerability in versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 that allows attackers to take over the system without authentication. An attacker only needs network access via TCP to exploit this flaw, and the vulnerability has a very high severity score of 9.8 out of 10 (CVSS, a standard rating system for how serious security flaws are).
Vulnerability Details
CVSS Score
9.8(critical)
EPSS (30-day exploit probability)
EPSS: 0.0%
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
network
Attack Complexity
low
Privileges Required
none
User Interaction
none
Disclosure Date
July 21, 2026
Classification
Attack SophisticationModerate
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-60219
First tracked: July 22, 2026 at 02:07 AM
Classified by LLM (prompt v3) · confidence: 95%