Connect with us

Security

Oracle Takes Swift Action to Address Critical Identity Manager Vulnerability

Published

on

Oracle Releases Critical Security Update for Identity Manager and Web Services Manager

Update: Oracle has not confirmed if the vulnerability has been exploited.

Oracle has urgently issued a security update to address a critical unauthenticated remote code execution vulnerability in Identity Manager and Web Services Manager identified as CVE-2026-21992.

Identity Manager is a tool used for managing identities and access within an organization, while Web Services Manager offers security and management controls for web services.

In a recent advisory, Oracle strongly advises customers to apply the patches promptly to mitigate any potential risks.

The CVE-2026-21992 vulnerability has been given a severity score of 9.8 on the CVSS v3.1 scale and affects versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Identity Manager, as well as versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Web Services Manager.

According to Oracle, the vulnerability is of low complexity, can be exploited remotely over HTTP, and does not require authentication or user interaction, making it a high-risk issue for exposed servers.

The security fix has been released through Oracle’s Security Alert program, which addresses critical vulnerabilities that are actively being exploited. However, it is important to note that patches provided through this program are only available for actively supported versions, and older unsupported versions may still be vulnerable.

Oracle has refrained from disclosing if the vulnerability has been taken advantage of and has chosen not to comment on its exploitation status when questioned.

In a recent blog post, Oracle reiterated the seriousness of CVE-2026-21992 and urged customers to review the security alert for comprehensive details and patch information.

Trending