Update: Added that Oracle declined to comment on whether the vulnerability has been exploited. Oracle has released an out-of-band security update to fix a critical unauthenticated remote code execution vulnerability in Identity Manager and Web Services Manager tracked as CVE-2026-21992. Oracle Identity Manager is used for managing identities and access across an enterprise, while Oracle Web Services Manager provides security and management controls for web services. In an advisory released yesterday, Oracle is "strongly" recommending that customers apply the patches as soon as possible. "This Security Alert addresses vulnerability CVE-2026-21992 in Oracle Identity Manager and Oracle Web Services Manager. This vulnerability is remotely exploitable without authentication. If successfully exploited, this vulnerability may result in remote code execution," reads the security advisory. "Oracle strongly recommends that customers apply the updates or mitigations provided by this Security Alert as soon as possible. Oracle always recommends that customers remain on actively-supported versions and apply all Security Alerts and Critical Patch Update security patches without delay." The CVE-2026-21992 vulnerability has a CVSS v3.1 severity score of 9.8 and impacts Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0, as well as Oracle Web Services Manager versions 12.2.1.4.0 and 14.1.2.1.0. Oracle says the flaw is of low complexity, remotely exploitable over HTTP, and does not req...
Oracle pushes emergency fix for critical Identity Manager RCE flaw
BleepingComputer
·Lawrence Abrams
·Published Mar 20, 2026
·Updated
Affected Software
2 affected components
Oracle Identity Manager=12.2.1.4.0, =14.1.2.1.0
Oracle Web Services Manager=12.2.1.4.0, =14.1.2.1.0
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses an emergency security update released by Oracle to address a critical remote code execution vulnerability in Identity Manager and Web Services Manager.
2
What security implications are discussed in the article?
The article highlights a critical unauthenticated remote code execution vulnerability that could allow attackers to execute arbitrary code on affected systems.
3
What products or software are affected by the vulnerability?
The affected products are Oracle Identity Manager and Oracle Web Services Manager.
4
What is the identification code for the vulnerability?
The vulnerability is tracked as CVE-2026-21992.
5
Has the vulnerability been reported as exploited according to the article?
The article states that Oracle declined to comment on whether the vulnerability has been exploited.