CISA warns Oracle Identity Manager RCE flaw is being actively exploited
ID: 202653b7-daea-5203-9431-3b6bf74b43ee
STIX ID: report--202653b7-daea-5203-9431-3b6bf74b43ee
Feed Name: Bleeping Computer
Threat Score
**Executive summary:** CISA has warned that CVE-2025-61757, a pre-authentication RCE in Oracle Identity Manager that can be triggered by forcing protected REST endpoints to be treated as public and abusing a Groovy compilation endpoint, has been exploited in the wild; Oracle released fixes on October 21, 2025 and federal agencies were added to CISA's KEV with a mandated patching deadline.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
