CVE-2026-60224: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
criticalvulnerability
security
Summary
A critical vulnerability (CVE-2026-60224) exists in Oracle Coherence, a data management product used in Oracle Fusion Middleware, that allows an attacker without credentials to gain complete control of the system by sending malicious data over the network. The vulnerability affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, with a severity score (CVSS score, a 0-10 rating of how severe a vulnerability is) of 9.8 out of 10.
Vulnerability Details
CVSS Score
9.8(critical)
EPSS (30-day exploit probability)
EPSS: 0.0%
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
network
Attack Complexity
low
Privileges Required
none
User Interaction
none
Disclosure Date
July 21, 2026
Classification
Attack SophisticationTrivial
Impact (CIA+S)
confidentialityintegrityavailability
Affected Vendors
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-60224
First tracked: July 22, 2026 at 02:07 AM
Classified by LLM (prompt v3) · confidence: 35%