Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
cPanelSniper PoC Exploit for cPanel Vulner Disclosed Vulnerability
May 2, 2026
EtherRAT Targets Enterprise Admins with SEO Poison
May 1, 2026
New Spyware Platform: Rebrand & Resell Android Lets Buyers
May 1, 2026
Home/CyberSecurity News/Oracle Critical RCE Flaw: Urgent Security Update for
CyberSecurity News

Oracle Critical RCE Flaw: Urgent Security Update for

Oracle has issued an out-of-band Security Alert to address a critical remote code execution (RCE) vulnerability. Identified as CVE-2026-21992, this flaw affects two widely deployed Fusion Middleware...

Emy Elsamnoudy
Emy Elsamnoudy
March 21, 2026 2 Min Read
0 0

Oracle has issued an out-of-band Security Alert to address a critical remote code execution (RCE) vulnerability. Identified as CVE-2026-21992, this flaw affects two widely deployed Fusion Middleware components: Oracle Identity Manager and Oracle Web Services Manager.

The vulnerability carries a CVSS 3.1 base score of 9.8, placing it among the most severe classifications in Oracle’s risk framework.

CVE-2026-21992 is an unauthenticated, remotely exploitable flaw that requires no user interaction or special privileges to exploit. The attack vector is network-based with low complexity, meaning a threat actor only needs HTTP access to an exposed endpoint to potentially trigger remote code execution.

Both the Confidentiality, Integrity, and Availability impact categories are rated High, indicating that a successful exploit could grant an attacker full control over the affected system.

In Oracle Identity Manager, the vulnerability resides in the REST Web Services component, while in Oracle Web Services Manager, the flaw exists within the Web Services Security module.

Oracle notes that Web Services Manager is typically installed alongside Oracle Fusion Middleware Infrastructure, expanding the potential attack surface across enterprise deployments.

Affected Versions

The vulnerability impacts the following product versions:

Product Affected Versions
Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0
Oracle Web Services Manager 12.2.1.4.0, 14.1.2.1.0

Both affected versions fall under the Fusion Middleware patch track, with patch documentation available via Oracle’s Security Alert advisory page and My Oracle Support (Document ID KB878741).

A CVSS score of 9.8 with no authentication requirement makes this vulnerability particularly dangerous for organizations with internet-facing Oracle Fusion Middleware deployments.

Oracle Identity Manager is a widely used identity governance platform, and Oracle Web Services Manager handles security policy enforcement for web services both are critical infrastructure components in large enterprise and government environments. Exploitation of either could result in full system compromise, credential theft, or lateral movement across connected systems.

Oracle strongly urges all customers to apply the available patches immediately. The alert, initially released on March 19, 2026, received an updated revision on March 20, 2026, with an additional note from Oracle.

Organizations running unsupported versions of the affected products are advised to upgrade to a supported release, as patches are only provided for versions under Premier Support or Extended Support phases per Oracle’s Lifetime Support Policy.

Security teams should prioritize patching any externally accessible instances and review HTTP/HTTPS exposure of REST Web Services and Web Services Security endpoints until remediation is complete. Customers can reference the full risk matrix and verbose CVE details on Oracle’s official Security Alerts portal.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Anthropic Claude Desktop Gains New Projects Feature

Next Post

Chrome Update Fixes 26 Critical Remote Code Security Vulnerabilities

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
DDoS Attack Hits Ubuntu Website & Canonical Web Services
May 1, 2026
Ransomware Victims Jump to 7,831 as AI Crime Tools Scale Global
May 1, 2026
Deep#Door Stealer Harvests Passwords, Cloud Browser Tokens
May 1, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Sarah simpson
Sarah simpson
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us