• News/
  • https://www.bleepingcomputer.com/news/security/oracle-pushes-emergency-fix-for-critical-identity-manager-rce-flaw/

Oracle pushes emergency fix for critical Identity Manager RCE flaw

BleepingComputer
·
Lawrence Abrams
·
Published Mar 20, 2026
·
Updated

Update: Added that Oracle declined to comment on whether the vulnerability has been exploited. Oracle has released an out-of-band security update to fix a critical unauthenticated remote code execution vulnerability in Identity Manager and Web Services Manager tracked as CVE-2026-21992. Oracle Identity Manager is used for managing identities and access across an enterprise, while Oracle Web Services Manager provides security and management controls for web services. In an advisory released yesterday, Oracle is "strongly" recommending that customers apply the patches as soon as possible. "This Security Alert addresses vulnerability CVE-2026-21992 in Oracle Identity Manager and Oracle Web Services Manager. This vulnerability is remotely exploitable without authentication. If successfully exploited, this vulnerability may result in remote code execution," reads the security advisory. "Oracle strongly recommends that customers apply the updates or mitigations provided by this Security Alert as soon as possible. Oracle always recommends that customers remain on actively-supported versions and apply all Security Alerts and Critical Patch Update security patches without delay." The CVE-2026-21992 vulnerability has a CVSS v3.1 severity score of 9.8 and impacts Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0, as well as Oracle Web Services Manager versions 12.2.1.4.0 and 14.1.2.1.0. Oracle says the flaw is of low complexity, remotely exploitable over HTTP, and does not req...

Read full article

Affected Software

2 affected components
Oracle Identity Manager=12.2.1.4.0, =14.1.2.1.0
Oracle Web Services Manager=12.2.1.4.0, =14.1.2.1.0
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses an emergency security update released by Oracle to address a critical remote code execution vulnerability in Identity Manager and Web Services Manager.

2

What security implications are discussed in the article?

The article highlights a critical unauthenticated remote code execution vulnerability that could allow attackers to execute arbitrary code on affected systems.

3

What products or software are affected by the vulnerability?

The affected products are Oracle Identity Manager and Oracle Web Services Manager.

4

What is the identification code for the vulnerability?

The vulnerability is tracked as CVE-2026-21992.

5

Has the vulnerability been reported as exploited according to the article?

The article states that Oracle declined to comment on whether the vulnerability has been exploited.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203