CVE-2026-21992
CVSS 9.8 CRITICAL: vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and… EPSS 1% (58th percentile), up from 0.07%.
Vulnerabilities & Exploits · Web App Attack
Oracle issued an out-of-band security alert and patches for a critical vulnerability.
6 sources · Mar 23
CVSS 9.8 CRITICAL: vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and… EPSS 1% (58th percentile), up from 0.07%.
Help Net Security
Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992) - Help Net Security
Oracle has fixed an easily exploitable vulnerability (CVE-2026-21992) in Oracle Identity Manager and Oracle Web Services Manager.
originalSecurityWeek
Oracle Releases Emergency Patch for Critical Identity Manager Vulnerability
CVE-2026-21992 can be used without authentication for remote code execution and it may have been exploited in the wild.
originalThe Hacker News
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
Oracle fixes CVE-2026-21992 (CVSS 9.8) flaw enabling unauthenticated RCE via HTTP, risking full system compromise.
originalPart of the PlainSec briefing for 2026-03-22
Every edition of this story: Oracle Patches Critical Unauthenticated RCE in Fusion Middleware