A critical remote code execution vulnerability (CVE-2026-60217) has been disclosed in Oracle Coherence, a component of Oracle Fusion Middleware. The flaw exists in the Core module and impacts versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Attackers with network access via TCP can exploit this vulnerability without authentication to take control of affected systems. The vulnerability's CVSS 3.1 score of 10.0 reflects its high severity, with potential for full confidentiality, integrity, and availability compromise. Due to scope changes, exploitation could also impact other products within the middleware ecosystem. Organizations operating affected versions are strongly advised to apply patches from Oracle's latest security updates. In the absence of patches, network-level mitigations such as restricting TCP access to trusted sources and deploying intrusion prevention systems are recommended. This vulnerability underscores the importance of timely updates for enterprise middleware components, as exploitation could lead to widespread system breaches and operational disruption.
CRITICAL
CVSS 10.0
CVE-2026-60217
2026-08-13
Critical Remote Code Execution Vulnerability in Oracle Coherence (CVE-2026-60217)
A critical vulnerability in Oracle Coherence allows unauthenticated attackers to execute arbitrary code remotely. Affects multiple versions of Oracle Fusion Middleware. Immediate patching required to prevent system compromise.