CVE-2026-21992
CVSS 9.8 CRITICAL: vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and… EPSS 1% (58º percentile), in aumento rispetto a 0.07%.
Vulnerabilità ed exploit · Attacco ad app web
La falla è sfruttabile remotamente via HTTP, ha CVSSv3 9.8 e segue sfruttamento correlato in the wild (CVE-2025-61757).
6 fonti · 23 mar
CVSS 9.8 CRITICAL: vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and… EPSS 1% (58º percentile), in aumento rispetto a 0.07%.
Help Net Security
Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992) - Help Net Security
Oracle has fixed an easily exploitable vulnerability (CVE-2026-21992) in Oracle Identity Manager and Oracle Web Services Manager.
originaleSecurityWeek
Oracle Releases Emergency Patch for Critical Identity Manager Vulnerability
CVE-2026-21992 can be used without authentication for remote code execution and it may have been exploited in the wild.
originaleThe Hacker News
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
Oracle fixes CVE-2026-21992 (CVSS 9.8) flaw enabling unauthenticated RCE via HTTP, risking full system compromise.
originalePart of the PlainSec briefing for 2026-03-20
Every edition of this story: Oracle rilascia patch per RCE critica senza autenticazione