Top impactful security developments (2026-07-22 08:17) - 2 days summary
Most impactful security incidents / vulnerabilities reported between the last update (July 21‑22 2026) and today
| # | CVE ID | Affected product / component | Impact summary | CVSS 3.x Base Score (Vector) | Affected versions (Oracle Coherence) | Public source |
|---|---|---|---|---|---|---|
| 1 | CVE‑2026‑60308 | Oracle Coherence (Core) – part of Oracle Fusion Middleware | Remote, unauthenticated attacker can gain full control of the Coherence service (RCE / complete takeover). | 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | • CVE API • Oracle advisory |
| 2 | CVE‑2026‑60306 | Oracle Coherence (Core) | Same remote‑code‑execution / takeover scenario as above. | 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | • CVE API |
| 3 | CVE‑2026‑60300 | Oracle Coherence (Core) | Remote unauthenticated takeover of the Coherence service. | 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | • CVE API |
| 4 | CVE‑2026‑60299 | Oracle Coherence (Core) | Remote unauthenticated takeover via TCP/HTTP. | 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) | 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | • CVE API |
| 5 | CVE‑2026‑60298 | Oracle Coherence (Core) | Remote unauthenticated takeover via TCP/HTTP. | 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) | 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | • CVE API |
| 6 | CVE‑2026‑60297 | Oracle Coherence (Core) | Remote unauthenticated takeover via TCP/HTTP. | 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | • CVE API |
| 7 | CVE‑2026‑60296 | Oracle Coherence (Core) | Remote unauthenticated takeover via TCP/HTTP. | 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | • CVE API |
| 8 | CVE‑2026‑60295 (not listed but implied by the series) – if present would follow same pattern; however, only the above IDs are confirmed in the supplied data. |
Why these CVEs meet Priority 1
- Critical severity – All have a CVSS 3.x base score of 9.8, placing them at the top of the “critical” band.
- Remote code execution / full system takeover – The vulnerability is exploitable over the network (no authentication required) and grants complete control of Oracle Coherence, an essential caching/cluster component used in many enterprise applications.
- Broad version impact – Affected versions span multiple major releases (12.2‑15.x), meaning a large installed base across enterprises.
- No known mitigations at time of disclosure – The advisories only provide patch information; exploitation is trivial given the “network‑only” vector.
Additional high‑impact findings (lower priority)
| ID | Product | Score | Reason for inclusion |
|---|---|---|---|
| EUVD‑2026‑47358 – Oracle Commerce Guided Search / Experience Manager | 8.1/10 | High‑severity vulnerability in a widely deployed e‑commerce platform (score > 7). | |
| EUVD‑2026‑47359 – Same component | 7.1/10 | Still above the high‑severity threshold. | |
| EUVD‑2026‑47360 – Same component | 5.4/10 | Below the 7‑threshold, omitted from priority list but noted for completeness. |
Sources: EUVD entries are posted on the ENISA European Vulnerability Database (e.g., https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-47358).
Quick reference links
| Item | Link |
|---|---|
| CVE‑2026‑60308 details | https://cveawg.mitre.org/api/cve/CVE-2026-60308 |
| CVE‑2026‑60306 details | https://cveawg.mitre.org/api/cve/CVE-2026-60306 |
| CVE‑2026‑60300 details | https://cveawg.mitre.org/api/cve/CVE-2026-60300 |
| Oracle security advisory (July 2026) | https://www.oracle.com/security-alerts/cpujul2026.html |
| EUVD‑2026‑47358 (Oracle Commerce) | https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-47358 |
Take‑away:
The most critical incidents reported in the last few days are a cluster of CVE‑2026‑603xx vulnerabilities affecting Oracle Coherence. They provide unauthenticated remote code execution with a CVSS score of 9.8, impact multiple major releases, and therefore demand immediate patching or mitigation for any environment that runs Oracle Fusion Middleware/Coherence. The EUVD entries on Oracle Commerce are also high‑severity but sit just below the critical threshold. No zero‑day exploits, supply‑chain attacks, ransomware campaigns, or APT activity were identified in the supplied data set for this period.
Model=gpt-oss:120b top_k=70 context_window=131072 query_mode=cluster