CVE-2026-21992
CVSS 9.8 CRITICAL: vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and… EPSS 1% (58º percentile), in aumento rispetto a 0.07%.
Vulnerabilità · 160 giorni fa
Oracle’s April CPU is not a routine patch cycle for teams running Oracle Communications. The problem is the concentration of remotely exploitable, unauthenticated flaws, which means exposed systems can be attacked before any login barrier gets in the way.
Oracle released 481 new security patches across 28 product families, with more than 300 fixes for remotely exploitable, unauthenticated vulnerabilities and roughly 450 unique CVEs on the update page. Oracle Communications received 139 patches, including 93 for unauthenticated remote issues; Financial Services Applications and Fusion Middleware were the next largest buckets.
For defenders, the immediate risk is not the patch count itself. It is the number of Oracle products that now carry internet-reachable attack surface, with Oracle Communications standing out as the most concentrated exposure area in this cycle.
CVSS 9.8 CRITICAL: vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and… EPSS 1% (58º percentile), in aumento rispetto a 0.07%.
3 fonti che coprono questa storia
Oracle Critical Patch Update, April 2026 Security Update Review | Qualys
Oracle released its second quarterly edition of this year’s Critical Patch Update.
Oracle Patches 450 Vulnerabilities With April 2026 CPU
The company released 481 new security patches across 28 product families, including over 300 fixes for remotely exploitable, unauthenticated flaws.
Oracle Apr 2026 Critical Patch Update 241 CVEs | Tenable®
Oracle addresses 241 CVEs in its April Critical Patch Update, the second quarterly update of 2026 with 481 patches, including 34 critical updates.
Part of the PlainSec briefing for 2026-04-23