CVE-2026-60222: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
highvulnerability
security
Summary
Oracle Coherence, a data management product in Oracle Fusion Middleware, has a vulnerability (CVE-2026-60222) that allows an unauthenticated attacker with network access to take over the system through T3 or IIOP protocols (communication protocols used for remote connections). The vulnerability affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, and has a severity score (CVSS score) of 8.1, meaning it poses a serious risk to confidentiality, integrity, and availability of data.
Vulnerability Details
CVSS Score
8.1(high)
EPSS (30-day exploit probability)
EPSS: 0.0%
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
network
Attack Complexity
high
Privileges Required
none
User Interaction
none
Disclosure Date
July 21, 2026
Classification
Attack SophisticationModerate
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-60222
First tracked: July 22, 2026 at 02:07 AM
Classified by LLM (prompt v3) · confidence: 95%