logo

Oracle Issues Emergency Patch for Critical Flaw Enabling Remote Code Execution

ID: 8728b73d-68ea-5ce5-a4a8-73bc00c9e2c5

STIX ID: report--8728b73d-68ea-5ce5-a4a8-73bc00c9e2c5

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2026-03-24

Date Updated: 2026-05-05

Author: Ashish Khaitan

...
...

Oracle issued an emergency out-of-band patch for CVE-2026-21992, a critical (CVSS 9.8) unauthenticated remote code execution vulnerability affecting Oracle Identity Manager and Oracle Web Services Manager (versions 12.2.1.4.0 and 14.1.2.1.0); the flaw can be triggered over HTTP without credentials, potentially allowing full system compromise of identity infrastructure, and customers are urged to apply patches immediately though Oracle has not confirmed active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.