CVE-2026-60217: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Summary
Oracle Coherence, a distributed data management product in Oracle Fusion Middleware, has a critical vulnerability (CVE-2026-60217) that allows attackers without authentication to take over the system through network access via TCP. The vulnerability affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, with a maximum severity score of 10.0 out of 10, meaning attackers could gain complete control over data confidentiality (reading data), integrity (modifying data), and availability (taking systems offline).
Vulnerability Details
10(critical)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
network
low
none
none
July 21, 2026
Classification
Affected Vendors
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-60217
First tracked: July 22, 2026 at 02:07 AM
Classified by LLM (prompt v3) · confidence: 45%