Vulnerabilities & Exploits · Web App Attack

Oracle Patches Critical Unauthenticated RCE in Fusion Middleware

Oracle issued an out-of-band security alert and patches for a critical vulnerability.

6 sources · Mar 23

CVE-2026-21992

NVD KEV

CVSS 9.8 CRITICAL: vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and… EPSS 1% (58th percentile), up from 0.07%.

Timeline

Sources

Part of the PlainSec briefing for 2026-03-22

Every edition of this story: Oracle Patches Critical Unauthenticated RCE in Fusion Middleware

More from today