Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
ID: 4b5deada-9d80-5b8c-bb28-cf1f5da7c546
STIX ID: report--4b5deada-9d80-5b8c-bb28-cf1f5da7c546
Feed Name: The Hacker News
Threat Score
Oracle has released patches for **CVE-2026-21992**, a critical (CVSS 9.8) unauthenticated remote code execution vulnerability impacting Oracle Identity Manager and Oracle Web Services Manager (versions 12.2.1.4.0 and 14.1.2.1.0). The NVD characterizes the flaw as "easily exploitable" over HTTP; Oracle reports no current in-the-wild exploitation but strongly urges immediate application of the updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
