logo

Oracle Fixes High-Severity RCE Vulnerability Affecting Identity and Web Services Platforms

ID: 4368d3df-1af7-51f6-ae8e-34fd2dde92b8

STIX ID: report--4368d3df-1af7-51f6-ae8e-34fd2dde92b8

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-21

Date Updated: 2026-04-22

Author: Divya

...
...

Oracle has issued an urgent advisory for CVE-2026-21992, a critical unauthenticated remote code execution vulnerability affecting Oracle Identity Manager and Oracle Web Services Manager (notably versions 12.2.1.4.0 and 14.1.2.1.0). The flaw permits attackers to execute arbitrary code over standard network protocols (including HTTPS) without authentication; Oracle recommends applying the Fusion Middleware patch KB878741 and upgrading unsupported versions, and security teams are urged to deploy fixes immediately to prevent system compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.