CISA has ordered US federal agencies to patch against an actively exploited Oracle Identity Manager (OIM) flaw within three weeks – a scramble made more urgent by evidence that attackers may have been abusing the bug months before a fix was released. The flaw, tracked as CVE-2025-61757 and now sitting in CISA's Known Exploited Vulnerabilities catalog, is "easily exploitable" and allows an unauthenticated attacker with network access to compromise OIM, enabling a full takeover of the system. "Oracle Fusion Middleware contains a missing authentication for a critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager," CISA warned. Agencies have been told to patch the vulnerability by December 12 or face the usual federal compliance consequences. Searchlight Cyber researchers Adam Kues and Shubham Shah, who discovered the flaw, have published their own technical teardown of the vulnerability that doesn't mince words about the ease with which criminals can weaponize it. The researchers call exploitation "trivial," describing a single HTTP request that bypasses OIM's normal authentication flow and ultimately gives an attacker remote system-level control. Oracle disclosed the bug in October, but didn't indicate that it was under active exploitation. However, analysis from SANS ISC dean Johannes Ullrich suggests attackers may have known about the flaw long before Oracle did. In traffic logs Ullrich reviewed, the telltale OIM exploit URL a...
CISA orders feds to patch Oracle Identity Manager zero-day after signs of abuse
The Register
·Carly Page
·Published Nov 24, 2025
·Updated
Affected Software
2 affected components
Oracle Identity Manager
Oracle Fusion Middleware
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a zero-day vulnerability in Oracle Identity Manager that is being actively exploited, prompting CISA to issue a patch mandate for federal agencies.
2
What security implications are discussed?
The article highlights the urgency of patching the Oracle Identity Manager flaw due to evidence of it being exploited by attackers.
3
What products or software are affected?
The affected products mentioned in the article include Oracle Identity Manager and Oracle Fusion Middleware.
4
What actions has CISA taken regarding this vulnerability?
CISA has ordered federal agencies to implement patches for the Oracle Identity Manager flaw within three weeks.
5
Why is the patching of Oracle Identity Manager considered urgent?
The patching is urgent due to signs that the vulnerability is already being abused in the wild.