CVE-2026-60197: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Summary
A critical vulnerability exists in Oracle Coherence (a data storage and management product) that allows an attacker without authentication to take over the system by sending specially crafted data over a network connection. The vulnerability affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, and has a CVSS score (a 0-10 rating of how severe a vulnerability is) of 9.8, indicating it is extremely serious and could compromise the confidentiality, integrity, and availability of the affected system.
Vulnerability Details
9.8(critical)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
network
low
none
none
July 21, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-60197
First tracked: July 22, 2026 at 02:07 AM
Classified by LLM (prompt v3) · confidence: 95%