logo

CVE-2026-21992: Critical Out-of-Band Oracle Identity Manager and Oracle Web Services Manager Remote Code Execution Vulnerability

ID: 9b7a3fd6-0f0a-5011-b697-995b8e12cb7a

STIX ID: report--9b7a3fd6-0f0a-5011-b697-995b8e12cb7a

Feed Name: Tenable Blog

Threat Score
85/100

Date Published: 2026-03-20

Date Updated: 2026-05-01

Author: Satnam Narang

...
...

Oracle issued an out-of-band security alert for CVE-2026-21992, a critical unauthenticated remote code execution vulnerability (CVSSv3 9.8) affecting Oracle Identity Manager and Oracle Web Services Manager; Oracle released patches for the affected versions, no public proof-of-concept was available at publication, and the alert follows recent in-the-wild exploitation of a related 2025 vulnerability (CVE-2025-61757) that was added to CISA's KEV catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.