CVE-2026-21992
CVSS 9.8 CRITICAL: vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and… EPSS 1% (58th percentile), up from 0.07%.
Vulnerabilities & Exploits · Web App Attack
The flaw permits unauthenticated attackers over HTTP(S) to achieve remote code execution and has a CVSS score of 9.8. Affected versions include 12.2.1.4.0 and 14.1.2.1.0; unsupported earlier releases are likely affected.
6 sources · Mar 23
CVSS 9.8 CRITICAL: vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and… EPSS 1% (58th percentile), up from 0.07%.
Help Net Security
Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992) - Help Net Security
Oracle has fixed an easily exploitable vulnerability (CVE-2026-21992) in Oracle Identity Manager and Oracle Web Services Manager.
originalSecurityWeek
Oracle Releases Emergency Patch for Critical Identity Manager Vulnerability
CVE-2026-21992 can be used without authentication for remote code execution and it may have been exploited in the wild.
originalThe Hacker News
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
Oracle fixes CVE-2026-21992 (CVSS 9.8) flaw enabling unauthenticated RCE via HTTP, risking full system compromise.
originalPart of the PlainSec briefing for 2026-03-24
Every edition of this story: Oracle Patches Critical Unauthenticated RCE in Fusion Middleware