logo

Oracle fixes critical RCE flaw CVE-2026-21992 in Identity Manager

ID: 4578bf52-0663-5d2f-b8b4-5a3f04f98eee

STIX ID: report--4578bf52-0663-5d2f-b8b4-5a3f04f98eee

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-03-22

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Oracle released fixes for a critical unauthenticated RCE in Identity Manager and Web Services Manager (CVE-2026-21992 / CVSS 9.8) affecting versions 12.2.1.4.0 and 14.1.2.1.0; honeypot data shows multiple HTTP POST attempts consistent with active exploitation prior to the patch, and Oracle recommends immediate application of the provided updates or mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.