Oracle Patches Critical Unauthenticated RCE in Fusion Middleware

Oracle released out-of-band fixes for a critical unauthenticated remote-code-execution vulnerability (CVE-2026-21992) in Oracle Identity Manager and Oracle Web Services Manager.

Part of the PlainSec briefing for 2026-03-25

Sources