CVE-2026-60223: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
highvulnerability
security
Summary
Oracle Coherence, a data management product in Oracle Fusion Middleware, has a vulnerability (CVE-2026-60223) that allows an attacker without authentication to connect over a network and crash the system, making it unavailable (a denial-of-service attack). The vulnerability affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, and has a CVSS score (a 0-10 rating of severity) of 7.5, indicating a serious issue.
Vulnerability Details
CVSS Score
7.5(high)
EPSS (30-day exploit probability)
EPSS: 0.0%
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
network
Attack Complexity
low
Privileges Required
none
User Interaction
none
Disclosure Date
July 21, 2026
Classification
Attack SophisticationTrivial
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-60223
First tracked: July 22, 2026 at 02:07 AM
Classified by LLM (prompt v3) · confidence: 95%