logo

Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager

ID: 4b5deada-9d80-5b8c-bb28-cf1f5da7c546

STIX ID: report--4b5deada-9d80-5b8c-bb28-cf1f5da7c546

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-03-21

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Oracle has released patches for **CVE-2026-21992**, a critical (CVSS 9.8) unauthenticated remote code execution vulnerability impacting Oracle Identity Manager and Oracle Web Services Manager (versions 12.2.1.4.0 and 14.1.2.1.0). The NVD characterizes the flaw as "easily exploitable" over HTTP; Oracle reports no current in-the-wild exploitation but strongly urges immediate application of the updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.