PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60233 Oracle CVE debrief

A vulnerability was discovered in Oracle Coherence, a product of Oracle Fusion Middleware, specifically in the Core component. The affected version is 15.1.1.0.0. This vulnerability allows a low-privileged attacker with network access via TCP to compromise Oracle Coherence, potentially leading to a partial denial of service (partial DOS). The CVSS 3.1 Base Score is 4.3, indicating a medium severity. Organizations should review their deployments and consider applying patches or mitigations to reduce the risk of exploitation.

Vendor
Oracle
Product
Coherence
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-27
Advisory published
2026-07-21
Advisory updated
2026-07-27

Who should care

Organizations using Oracle Coherence version 15.1.1.0.0 should be aware of this vulnerability and take necessary precautions to mitigate the risk. This includes reviewing their deployments, applying patches or updates provided by Oracle, restricting network access to Oracle Coherence, and monitoring logs for potential exploitation attempts. Additionally, organizations should consider implementing additional security controls, such as firewalls or intrusion detection systems, to reduce the risk of exploitation.

Technical summary

The vulnerability is located in the Core component of Oracle Coherence, a product of Oracle Fusion Middleware. A low-privileged attacker with network access via TCP can exploit this vulnerability to compromise Oracle Coherence, resulting in a partial denial of service (partial DOS). The CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L. The vulnerability allows a low-privileged attacker with network access via TCP to compromise Oracle Coherence, potentially leading to a partial denial of service (partial DOS). The CVSS 3.1 Base Score is 4.3, indicating a medium severity.

Defensive priority

Medium priority should be given to patching or mitigating this vulnerability, as it can be exploited by a low-privileged attacker with network access. Implementing additional security controls, such as firewalls or intrusion detection systems, may also be beneficial in reducing the risk of exploitation. It is essential to monitor Oracle Coherence logs for potential exploitation attempts and restrict network access to only necessary personnel. Furthermore, organizations should consider conducting a thorough review of their Oracle Coherence deployments to identify potential vulnerabilities and develop a plan to address them. This may involve coordinating with Oracle support and security teams to ensure that all necessary steps are taken to protect against potential threats. Additionally, organizations should verify that their incident response plan is up-to-date and includes procedures for responding to potential exploitation attempts. By taking these steps, organizations can help to minimize the risk of exploitation and protect their systems from potential harm. The vulnerability is located in the Core component of Oracle Coherence, and a low-privileged attacker with network access via TCP can exploit this vulnerability to compromise Oracle Coherence, resulting in a partial denial of service (partial DOS). The CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L. To address this vulnerability, organizations should prioritize patching or mitigating the vulnerability, as well as implementing additional security controls to reduce the risk of exploitation. This may involve applying patches or updates provided by Oracle, restricting network access to Oracle Coherence, and monitoring logs for potential exploitation attempts. By taking these steps, organizations can help to protect their systems from potential harm and minimize the risk of exploitation. The CVSS 3.1 Base Score is 4.3, indicating a medium severity, and the CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L. The vulnerability allows a low-privileged attacker with network access via TCP to compromise Oracle Coherence, potentially leading to a partial denial of service (partial DOS). The CV

Recommended defensive actions

  • Apply the patch or update provided by Oracle to fix the vulnerability.
  • Restrict network access to Oracle Coherence to only necessary personnel.
  • Monitor Oracle Coherence logs for potential exploitation attempts.
  • Consider implementing additional security controls, such as firewalls or intrusion detection systems.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record was published on 2026-07-21T22:17:25.060Z and was last modified on 2026-07-27T13:27:58.673Z. The NVD entry is currently Analyzed. This information is based on the provided source corpus. Further verification is recommended to ensure accuracy.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:25.060Z and has not been modified since then. The NVD entry is currently Analyzed.