CVE-2026-60272
CVE-2026-60272 is a critical vulnerability in Oracle Coherence (versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) that allows unauthenticated attackers with network access via HTTP to take control of the system. It has a CVSS score of 9.8, indicating high risks to confidentiality, integrity, and availability.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Real-world impact
Unauthenticated attackers can exploit this vulnerability to compromise Oracle Coherence systems, potentially leading to full system takeover.
Why this severity
CVSS 9.8 (critical) due to high impacts on all three security properties: confidentiality, integrity, and availability.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No official fix documented in provided sources (NVD description does not mention a patch or required action).
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 27, 2026 · 5d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- oracle.com/security-alerts/cpujul2026.…vendor advisory