Oracle Issues Emergency Patch for Critical Flaw Enabling Remote Code Execution
ID: 8728b73d-68ea-5ce5-a4a8-73bc00c9e2c5
STIX ID: report--8728b73d-68ea-5ce5-a4a8-73bc00c9e2c5
Feed Name: The Cyber Express
Threat Score
Oracle issued an emergency out-of-band patch for CVE-2026-21992, a critical (CVSS 9.8) unauthenticated remote code execution vulnerability affecting Oracle Identity Manager and Oracle Web Services Manager (versions 12.2.1.4.0 and 14.1.2.1.0); the flaw can be triggered over HTTP without credentials, potentially allowing full system compromise of identity infrastructure, and customers are urged to apply patches immediately though Oracle has not confirmed active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
