Critical Vulnerabilities in Oracle Coherence and Access Manager Disclosed
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Multiple vulnerabilities affecting Oracle Coherence and Oracle Access Manager have been disclosed. CVE-2026-60248 and CVE-2026-60295 are critical vulnerabilities in Oracle Coherence, allowing attackers to potentially take over the system. CVE-2026-60248 has a CVSS score of 9.3, while CVE-2026-60295 has a score of 8.5, indicating high risk. Both vulnerabilities require network access, with CVE-60248 allowing unauthenticated access. CVE-2026-60358, affecting Oracle Access Manager, has a CVSS score of 10.0, indicating a severe risk of remote code execution. All vulnerabilities were published on July 21, 2026, and Oracle has included them in its July 2026 Critical Patch Update advisory. However, the availability of patches for the affected versions is not confirmed. Organizations using these products are advised to monitor Oracle's channels for updates and apply patches promptly.
Key Points: • CVE-2026-60248 and CVE-2026-60295 allow potential takeover of Oracle Coherence. • CVE-2026-60358 in Oracle Access Manager has a critical CVSS score of 10.0. • Patches for the affected Oracle products are not yet confirmed.