Oracle pushes emergency fix for critical Identity Manager RCE flaw
ID: 9b781628-521f-5add-881a-8912228ad710
STIX ID: report--9b781628-521f-5add-881a-8912228ad710
Feed Name: Bleeping Computer
Oracle released an out-of-band security update for CVE-2026-21992, a critical (CVSS 9.8) unauthenticated remote code execution vulnerability affecting Oracle Identity Manager and Oracle Web Services Manager (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw is remotely exploitable over HTTP with low complexity and requires no authentication or user interaction; Oracle strongly urges customers to apply the provided patches or mitigations immediately and has not confirmed whether the vulnerability has been exploited in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
