Oracle Coherence: 96 records in one advisory
96 records announced together, published 2026-07-21, every one of them citing the same advisory.
The advisory
Every record in this batch cites https://www.oracle.com/security-alerts/cpujul2026.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.
What the records offer
No record in this batch publishes a fixed version in held sources.
No record in this batch is listed by CISA in held sources.
Held sources describe every record in this batch identically. Nothing but the identifier and the publication time separates one from another here.
Most commonly mapped weakness across the batch: Easily exploitable vulnerability allows…
What this page does not cover
This batch is 96 of the 1107 records that cite the same advisory. The other 1011 are different findings announced alongside it.
93 of them are on the sibling batches linked below. The remaining 918 are grouped with nothing and have only their own record pages.
Other batches under the same advisory: oracle-cpujul2026-7edf7124bf, oracle-cpujul2026-92cb9b3435, oracle-cpujul2026-aa4c3b68f0, oracle-cpujul2026-ab9cb50c62
The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.
What this batch was researched, not held
Oracle's biggest patch day, 100 Coherence rows, one researcher named
Oracle's July 2026 Critical Patch Update went out on 21 July 2026 carrying 1,448 patches, the largest the company has issued, 355 of them for Fusion Middleware. One hundred rows in it name Oracle Coherence, and 98 of those sit in a single component called Core. Exactly one of the hundred has a person attached to it. The advisory's credit statement thanks Trung Nguyen of CyStack for CVE-2026-60300 and names no other Coherence identifier, so for the remaining 99 Oracle says nothing about who reported them. What the advisory does say is severe. 81 of the hundred are marked reachable by an attacker with no credentials. 62 are reached over TCP and 28 over HTTP. 56 carry a base score of 9.8, and one, CVE-2026-60217 in Coherence Core, carries 10.0, the top of the scale. 78 name the same four affected releases, 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. The identifiers themselves run in two nearly unbroken blocks, CVE-2026-60209 to CVE-2026-60290 and CVE-2026-60295 to CVE-2026-60309.
Numbers that run one after another are a clerical fact. They tell you the identifiers were handed out in one go and nothing about whether the underlying problems are related. What a record here does tell you is that Oracle shipped a Coherence fix in the July 2026 quarterly bundle, on the same day as the others and for reasons the advisory does not print.
Oracle publishes a component name and a scoring vector and nothing else, so this batch cannot give you a bug class, the affected code, what the patch changed, or, for 99 of the 100 Coherence rows, who found it. Silence in the credit statement is not evidence that nobody outside Oracle reported them. The group also holds 96 records against the advisory's 98 Core rows, so two rows in Oracle's own table are not in this group and nothing here explains why.
Written from oracle.com, waratek.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
96 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.