• News/
  • https://www.bleepingcomputer.com/news/security/cisa-warns-oracle-identity-manager-rce-flaw-is-being-actively-exploited/

CISA warns Oracle Identity Manager RCE flaw is being actively exploited

BleepingComputer
·
Lawrence Abrams
·
Published Nov 21, 2025
·
Updated

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) is warning government agencies to patch an Oracle Identity Manager tracked as CVE-2025-61757 that has been exploited in attacks, potentially as a zero-day. CVE-2025-61757 is a pre-authentication RCE vulnerability in Oracle Identity Manager, discovered and disclosed by Searchlight Cyber analysts Adam Kues and Shubham Shahflaw. The flaw stems from an authentication bypass in Oracle Identity Manager's REST APIs, where a security filter can be tricked into treating protected endpoints as publicly accessible by appending parameters like ?WSDL or ;.wadl to URLpaths. Once unauthenticated access is gained, attackers can reach a Groovy script, which is a compilation endpoint that does not typically execute a script. However, it can be abused to run malicious code at compile time through Groovy's annotation-processing features. This chain of flaws enabled the researchers to achieve pre-authentication remote code execution on affected Oracle Identity Manager instances. The flaw was fixed as part of Oracle's October 2025 security updates, released on October 21. Yesterday, Searchlight Cyber released a technical report detailing the flaw and providing all the information required to exploit it. "Given the complexity of some previous Oracle Access Manager vulnerabilities, this one is somewhat trivial and easily exploitable by threat actors," warned the researchers. Today, CISA has added the Oracle CVE-2025-61757 vulnerability ...

Read full article

Affected Software

1 affected component
Oracle Identity Manager
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical remote code execution flaw in Oracle Identity Manager that is being actively exploited.

2

What security implications are discussed?

The article highlights the risk posed by the vulnerability CVE-2025-61757, which may allow attackers to execute arbitrary code on affected systems.

3

What products or software are affected?

The vulnerability specifically affects Oracle Identity Manager.

4

Who issued the warning about the vulnerability?

The warning was issued by the U.S. Cybersecurity & Infrastructure Security Agency (CISA).

5

What should organizations do in response to this vulnerability?

Organizations are urged to apply patches and updates to mitigate the risk of exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203