Critical Vulnerability (CVE-2021-35587) in Oracle Fusion Middleware Now Exploited!
ID: 69d22a75-fdaf-5655-b21f-b16d81b2c38b
STIX ID: report--69d22a75-fdaf-5655-b21f-b16d81b2c38b
Feed Name: Censys Blog
Date Published: 2022-12-01
Date Updated: 2026-04-27
Author: Ivonne Francia; Jill Cagliostro; Principal Product Management
CISA added CVE-2021-35587 — a critical pre-auth RCE in Oracle Access Manager enabling full takeover of Oracle Access Manager — to its Known Exploited Vulnerabilities Catalog after evidence of active exploitation; GreyNoise observed exploitation attempts from multiple countries and Censys reports 151 internet-exposed Oracle Access Manager hosts, with the post providing Censys queries and ASM risk guidance to help identify and mitigate exposed systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
