Vulnerabilities & Exploits · Web App Attack

Oracle Patches Critical Unauthenticated RCE in Fusion Middleware

The flaw permits unauthenticated attackers over HTTP(S) to achieve remote code execution and has a CVSS score of 9.8. Affected versions include 12.2.1.4.0 and 14.1.2.1.0; unsupported earlier releases are likely affected.

6 sources · Mar 23

CVE-2026-21992

NVD KEV

CVSS 9.8 CRITICAL: vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and… EPSS 1% (58th percentile), up from 0.07%.

Timeline

Sources

Part of the PlainSec briefing for 2026-03-24

Every edition of this story: Oracle Patches Critical Unauthenticated RCE in Fusion Middleware

More from today