logo

Critical Vulnerability (CVE-2021-35587) in Oracle Fusion Middleware Now Exploited!

ID: 69d22a75-fdaf-5655-b21f-b16d81b2c38b

STIX ID: report--69d22a75-fdaf-5655-b21f-b16d81b2c38b

Feed Name: Censys Blog

Threat Score
75/100

Date Published: 2022-12-01

Date Updated: 2026-04-27

Author: Ivonne Francia; Jill Cagliostro; Principal Product Management

...
...

CISA added CVE-2021-35587 — a critical pre-auth RCE in Oracle Access Manager enabling full takeover of Oracle Access Manager — to its Known Exploited Vulnerabilities Catalog after evidence of active exploitation; GreyNoise observed exploitation attempts from multiple countries and Censys reports 151 internet-exposed Oracle Access Manager hosts, with the post providing Censys queries and ASM risk guidance to help identify and mitigate exposed systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.