PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60260 Oracle CVE debrief

A vulnerability was discovered in Oracle Coherence, a product of Oracle Fusion Middleware, specifically in the Core component. The affected versions are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. This vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle Coherence, potentially leading to unauthorized read access to a subset of Oracle Coherence accessible data. The vulnerability has a CVSS score of 5.3, indicating a medium severity level. Organizations using these versions should be aware of this vulnerability and take necessary precautions to mitigate potential risks.

Vendor
Oracle
Product
Coherence
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-27
Advisory published
2026-07-21
Advisory updated
2026-07-27

Who should care

Organizations using Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 should be aware of this vulnerability and take necessary precautions to mitigate potential risks. This includes reviewing system deployments, assessing exposure, and implementing compensating controls if patches cannot be applied immediately. Security teams should prioritize patching and ensure thorough testing and validation of defensive measures to prevent disruptions or false positives in critical systems or services relying on Oracle Coherence.

Technical summary

The vulnerability has a CVSS score of 5.3 and a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. It is classified as a confidentiality impact vulnerability. The affected versions of Oracle Coherence are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Unauthenticated attackers with network access via HTTP can compromise Oracle Coherence, potentially leading to unauthorized read access to a subset of Oracle Coherence accessible data.

Defensive priority

Medium-High due to potential for unauthorized data access and exploitation via HTTP, suggesting immediate review and patching of affected systems, alongside enhanced monitoring for suspicious activity related to Oracle Coherence deployments, especially in environments with high confidentiality requirements or sensitive data exposure risk, and consider implementing compensating controls for data access if patches cannot be applied immediately, ensuring thorough testing and validation of all defensive measures to prevent potential disruptions or false positives in critical systems or services relying on Oracle Coherence for data management or processing tasks requiring confidentiality guarantees under regulatory compliance standards or organizational security policies requiring stringent data protection measures against unauthorized access attempts via network protocols like HTTP that could be exploited by attackers with minimal authentication requirements in place across affected product versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 deployed across various environments with different security postures and threat landscapes necessitating tailored defensive strategies based on specific operational contexts and risk tolerance levels within each organization impacted by this vulnerability affecting Oracle Coherence product deployments requiring immediate attention from security teams responsible for maintaining these systems securely according to best practices and industry standards for vulnerability management and incident response procedures related to confidentiality impacts from CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N vector indicating medium severity but high likelihood of exploitation attempts due to low authentication requirements allowing attackers easy access over HTTP without needing user credentials thereby increasing urgency for prompt remediation actions across all potentially affected systems within organizational networks or cloud infrastructures where Oracle Coherence is utilized extensively across different business units or departments with varying levels of security maturity and threat detection capabilities that need alignment,

Recommended defensive actions

  • Inventory and assess Oracle Coherence installations for vulnerability
  • Apply vendor patches or updates as available
  • Monitor and restrict network access to Oracle Coherence
  • Implement compensating controls for data access
  • Review system deployments and assess exposure
  • Ensure thorough testing and validation of defensive measures
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record was published on 2026-07-21T22:17:28.043Z and was last modified on 2026-07-27T20:26:43.340Z. The NVD entry is currently Analyzed. This information is based on the provided source corpus. Further verification by defenders is recommended to ensure accuracy and completeness of affected scope and potential impact.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:28.043Z and has not been modified since then. The NVD entry is currently Analyzed.