Cybersecurity & Privacy — 2026-03-23

Oracle Issues Emergency Patch for CVSS 9.8 RCE Flaw in Identity Manager; No Authentication Required

Oracle released an out-of-band emergency patch for CVE-2026-21992, a CVSS 9.8 critical vulnerability in Oracle Identity Manager and Web Services Manager that allows unauthenticated remote code execution over HTTP. The flaw affects versions 12.2.1.4.0 and 14.1.2.1.0. While Oracle has not reported active exploitation, the low-complexity attack vector and no-auth requirement make weaponization likely. The patch was issued outside Oracle's regular quarterly cycle, underscoring severity. A related Identity Manager flaw (CVE-2025-61757) was added to CISA's KEV catalog as actively exploited in November 2025.

2 sources
  1. Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager - The Hacker News
  2. Oracle fixes critical RCE flaw CVE-2026-21992 in Identity Manager - Security Affairs

View in full brief →

UNCLASSIFIED // OPEN SOURCE