logo

Oracle pushes emergency fix for critical Identity Manager RCE flaw

ID: 9b781628-521f-5add-881a-8912228ad710

STIX ID: report--9b781628-521f-5add-881a-8912228ad710

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-03-20

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Oracle released an out-of-band security update for CVE-2026-21992, a critical (CVSS 9.8) unauthenticated remote code execution vulnerability affecting Oracle Identity Manager and Oracle Web Services Manager (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw is remotely exploitable over HTTP with low complexity and requires no authentication or user interaction; Oracle strongly urges customers to apply the provided patches or mitigations immediately and has not confirmed whether the vulnerability has been exploited in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.