logo

Oracle vulnerability (CVE-2026-21992) impacts core products

ID: d922885b-e032-5113-8819-ecfb1008bbc8

STIX ID: report--d922885b-e032-5113-8819-ecfb1008bbc8

Feed Name: Sophos Blogs

Threat Score
75/100

Date Published: 2026-03-23

Date Updated: 2026-04-30

...
...

**Executive Summary:** Oracle disclosed a critical CVE-2026-21992 (CVSS 9.8) impacting Oracle Identity Manager and Oracle Web Services Manager that permits unauthenticated remote code execution via HTTP because key functions lack network-level authentication; no active exploitation has been reported and customers are advised to identify affected components and apply patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.