Security
Oracle Takes Swift Action to Address Critical Identity Manager Vulnerability
Oracle Releases Critical Security Update for Identity Manager and Web Services Manager
Update: Oracle has not confirmed if the vulnerability has been exploited.
Oracle has urgently issued a security update to address a critical unauthenticated remote code execution vulnerability in Identity Manager and Web Services Manager identified as CVE-2026-21992.
Identity Manager is a tool used for managing identities and access within an organization, while Web Services Manager offers security and management controls for web services.
In a recent advisory, Oracle strongly advises customers to apply the patches promptly to mitigate any potential risks.
The CVE-2026-21992 vulnerability has been given a severity score of 9.8 on the CVSS v3.1 scale and affects versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Identity Manager, as well as versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Web Services Manager.
According to Oracle, the vulnerability is of low complexity, can be exploited remotely over HTTP, and does not require authentication or user interaction, making it a high-risk issue for exposed servers.
The security fix has been released through Oracle’s Security Alert program, which addresses critical vulnerabilities that are actively being exploited. However, it is important to note that patches provided through this program are only available for actively supported versions, and older unsupported versions may still be vulnerable.
Oracle has refrained from disclosing if the vulnerability has been taken advantage of and has chosen not to comment on its exploitation status when questioned.
In a recent blog post, Oracle reiterated the seriousness of CVE-2026-21992 and urged customers to review the security alert for comprehensive details and patch information.
Malware tactics are evolving. The Red Report 2026 uncovers how new threats utilize mathematical methods to evade detection and remain unnoticed.
Access our analysis of 1.1 million malicious samples to uncover the top 10 techniques and assess the effectiveness of your security measures.
-
Facebook5 months agoEU Takes Action Against Instagram and Facebook for Violating Illegal Content Rules
-
Facebook5 months agoWarning: Facebook Creators Face Monetization Loss for Stealing and Reposting Videos
-
Facebook5 months agoFacebook Compliance: ICE-tracking Page Removed After US Government Intervention
-
Facebook3 months agoFacebook’s New Look: A Blend of Instagram’s Style
-
Facebook3 months agoFacebook and Instagram to Reduce Personalized Ads for European Users
-
Facebook5 months agoInstaDub: Meta’s AI Translation Tool for Instagram Videos
-
Facebook4 months agoReclaim Your Account: Facebook and Instagram Launch New Hub for Account Recovery
-
Apple5 months agoMeta discontinues Messenger apps for Windows and macOS

