CVE-2026-21992
CVSS 9.8 CRITICAL: vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and… EPSS 1% (58th percentile), up from 0.07%.
Vulnerabilities · 176 days ago
Oracle released out-of-band fixes for a critical unauthenticated remote-code-execution vulnerability (CVE-2026-21992) in Oracle Identity Manager and Oracle Web Services Manager.
CVSS 9.8 CRITICAL: vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and… EPSS 1% (58th percentile), up from 0.07%.
6 sources covering this story
Oracle has fixed an easily exploitable vulnerability (CVE-2026-21992) in Oracle Identity Manager and Oracle Web Services Manager.
Oracle Releases Emergency Patch for Critical Identity Manager Vulnerability
CVE-2026-21992 can be used without authentication for remote code execution and it may have been exploited in the wild.
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
Oracle fixes CVE-2026-21992 (CVSS 9.8) flaw enabling unauthenticated RCE via HTTP, risking full system compromise.
Patch Now: Oracle's Fusion Middleware Has Critical RCE Flaw
Attackers can execute arbitrary code without authentication if Oracle's Identity or Web Services Managers are exposed to the Web.
Oracle pushes emergency fix for critical Identity Manager RCE flaw
Oracle has released an out-of-band security update to fix a critical unauthenticated remote code execution vulnerability in Identity Manager and Web Services Manager tracked as CVE-2026-21992.
CVE-2026-21992: Oracle Fusion Middleware RCE | Tenable®
CVE-2026-21992 is a critical out-of-band Oracle Identity Manager/Web Services Manager RCE vulnerability.
Part of the PlainSec briefing for 2026-03-25