Critical Vulnerabilities in Oracle Coherence and Access Manager Disclosed

Critical Vulnerabilities in Oracle Coherence and Access Manager Disclosed

First seen 23 Jul 2026, 05:20 UTC Nvd.NistFeedlyLyrie.Airadar.offseq.comnvd.nist.gov+5 90% similarity 71.0

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities affecting Oracle Coherence and Oracle Access Manager have been disclosed. CVE-2026-60248 and CVE-2026-60295 are critical vulnerabilities in Oracle Coherence, allowing attackers to potentially take over the system. CVE-2026-60248 has a CVSS score of 9.3, while CVE-2026-60295 has a score of 8.5, indicating high risk. Both vulnerabilities require network access, with CVE-60248 allowing unauthenticated access. CVE-2026-60358, affecting Oracle Access Manager, has a CVSS score of 10.0, indicating a severe risk of remote code execution. All vulnerabilities were published on July 21, 2026, and Oracle has included them in its July 2026 Critical Patch Update advisory. However, the availability of patches for the affected versions is not confirmed. Organizations using these products are advised to monitor Oracle's channels for updates and apply patches promptly.

Key Points: • CVE-2026-60248 and CVE-2026-60295 allow potential takeover of Oracle Coherence. • CVE-2026-60358 in Oracle Access Manager has a critical CVSS score of 10.0. • Patches for the affected Oracle products are not yet confirmed.

ThreatCluster AI

Timeline

2026-07-21
CVE-2026-60295 published
Vulnerability allows low privileged attackers to compromise Oracle Coherence, CVSS 8.5.
Feedly
2026-07-21
CVE-2026-60248 published
Easily exploitable vulnerability in Oracle Coherence allows unauthenticated access, CVSS 9.3.
Lyrie.Ai
2026-07-21
CVE-2026-60358 published
Critical vulnerability in Oracle Access Manager allows remote code execution, CVSS 10.0.
cve.report
2026-07-21
CVE-2026-60233 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-23
Oracle Critical Patch Update advisory released
Oracle included multiple vulnerabilities in its July 2026 advisory, patch status not confirmed.
radar.offseq.com

Community

Browse all →