Oracle Fixes High-Severity RCE Vulnerability Affecting Identity and Web Services Platforms
ID: 4368d3df-1af7-51f6-ae8e-34fd2dde92b8
STIX ID: report--4368d3df-1af7-51f6-ae8e-34fd2dde92b8
Feed Name: GBHackers
Oracle has issued an urgent advisory for CVE-2026-21992, a critical unauthenticated remote code execution vulnerability affecting Oracle Identity Manager and Oracle Web Services Manager (notably versions 12.2.1.4.0 and 14.1.2.1.0). The flaw permits attackers to execute arbitrary code over standard network protocols (including HTTPS) without authentication; Oracle recommends applying the Fusion Middleware patch KB878741 and upgrading unsupported versions, and security teams are urged to deploy fixes immediately to prevent system compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
