logo

Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager

ID: c71d1631-5cf7-55af-8570-83ad24655b63

STIX ID: report--c71d1631-5cf7-55af-8570-83ad24655b63

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-03-21

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Oracle issued an out-of-band Security Alert for CVE-2026-21992, a critical unauthenticated network-accessible remote code execution vulnerability (CVSS 3.1 base score 9.8) affecting Oracle Identity Manager and Oracle Web Services Manager (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw resides in REST Web Services and Web Services Security components, can be exploited via HTTP with no authentication or user interaction, and Oracle strongly urges immediate patching and review of externally exposed endpoints to prevent full system compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.