
Oracle has provided fixes for a serious security problem in Identity Manager and Web Services Manager, which could let attackers remotely run code.
The security issue, known as CVE-2026-21992, has a severity score of 9.8 out of 10.0.
“This weakness can be exploited remotely without needing to log in,” Oracle stated in its alert. “Exploiting this successfully could lead to remote code execution.”
CVE-2026-21992 affects these versions –
A description in the NIST National Vulnerability Database (NVD) says the flaw is “easily exploitable.” It could allow an attacker without login credentials, who can access the network via HTTP, to compromise Oracle Identity Manager and Oracle Web Services Manager. This might allow them to take full control of vulnerable systems.
Oracle hasn’t said whether the vulnerability is currently being exploited. However, they are strongly advising customers to apply the update as soon as possible for the best protection.
In November 2025, CISA added CVE-2025-61757 (CVSS score: 9.8), a remote code execution flaw that doesn’t require login and affects Oracle Identity Manager, to its list of actively exploited vulnerabilities because there was evidence that it was being actively exploited.
#(cve-2026-21992) #code #execution #fixes #flaw #identity #login, #manager. #news #oracle #remote #severe #stopping #without — News
© Bulletproof Servers. All rights reserved.