logo

CISA Urges Patch of Actively Exploited Flaw in Oracle Identity Manager

ID: ca9170f3-b55f-5232-8cf2-0d99cdc68e94

STIX ID: report--ca9170f3-b55f-5232-8cf2-0d99cdc68e94

Feed Name: Infosecurity Magazine (News)

Threat Score
92/100

Date Published: 2025-11-24

Date Updated: 2026-04-22

...
...

A critical unauthenticated RCE in Oracle Identity Manager (CVE-2025-61757, CVSS 9.8) is being actively exploited in the wild and was added to CISA’s KEV catalog; attackers can execute arbitrary code over HTTP and potentially take over Identity Manager instances. CISA and Oracle recommend immediate patching or isolating affected services from the internet; the report also links the finding to a prior 2025 Oracle Cloud login breach that exposed ~6 million records and 140,000+ tenants.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.