Vulnerabilità ed exploit · Attacco ad app web

Oracle rilascia patch per RCE critica senza autenticazione

La falla è sfruttabile remotamente via HTTP, ha CVSSv3 9.8 e segue sfruttamento correlato in the wild (CVE-2025-61757).

6 fonti · 23 mar

CVE-2026-21992

NVD KEV

CVSS 9.8 CRITICAL: vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and… EPSS 1% (58º percentile), in aumento rispetto a 0.07%.

Cronologia

Fonti

Part of the PlainSec briefing for 2026-03-21

Every edition of this story: Oracle rilascia patch per RCE critica senza autenticazione

Altro da oggi