Skip to content

Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager

  • by

​Oracle has released security updates to address a critical security flaw impacting Identity Manager and Web Services Manager that could be exploited to achieve remote code execution.
The vulnerability, tracked as CVE-2026-21992, carries a CVSS score of 9.8 out of a maximum of 10.0.
“This vulnerability is remotely exploitable without authentication,” Oracle said in an advisory. “If successfully Oracle has released security updates to address a critical security flaw impacting Identity Manager and Web Services Manager that could be exploited to achieve remote code execution.
The vulnerability, tracked as CVE-2026-21992, carries a CVSS score of 9.8 out of a maximum of 10.0.
“This vulnerability is remotely exploitable without authentication,” Oracle said in an advisory. “If successfully  The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *