Vulnerabilities & Exploits · Web App Attack

Oracle Patches Critical Unauthenticated RCE in Fusion Middleware

Oracle released out-of-band fixes for a critical unauthenticated remote-code-execution vulnerability (CVE-2026-21992) in Oracle Identity Manager and Oracle Web Services Manager.

6 sources · Mar 23

CVE-2026-21992

NVD KEV

CVSS 9.8 CRITICAL: vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and… EPSS 1% (58th percentile), up from 0.07%.

Timeline

Sources

Part of the PlainSec briefing for 2026-03-25

Every edition of this story: Oracle Patches Critical Unauthenticated RCE in Fusion Middleware

More from today