logo

Patch Now: Oracle's Fusion Middleware Has Critical RCE Flaw

ID: 0c9ad958-b809-5430-8bc9-08891a16d5e9

STIX ID: report--0c9ad958-b809-5430-8bc9-08891a16d5e9

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-03-20

Date Updated: 2026-04-21

Author: Nate Nelson

...
...

Oracle issued an out-of-cycle security alert for CVE-2026-21992, a critical (CVSS 9.8) unauthenticated remote code execution flaw in Oracle Identity Manager and Oracle Web Services Manager that could allow attackers to manipulate identities, roles, and security policies or steal data; the bug affects specific OIM/OWSM versions used by many large enterprises, patching may be slow in complex environments, and while no public exploitation has been observed yet the potential impact and attackability are high.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.