HomeUpdatesOracle: Emergency update for vulnerability in Identity Manager

Oracle: Emergency update for vulnerability in Identity Manager

Oracle has issued an emergency security update for the critical vulnerability CVE-2026-21992 affecting Oracle Identity Manager and Oracle Web Services Manager . The vulnerability could allow unauthenticated attackers to execute code remotely and may have already been exploited in a malicious manner. This emergency action by Oracle reflects the severity of the threat and the need for immediate action by system administrators worldwide.

Oracle Identity Manager

Oracle issued the critical security update on March 20, 2026, outside of its regular quarterly Critical Patch Update cycle . This is not the first time this has happened. In November 2025, the company had previously issued a critical update for Oracle Identity Manager .

The vulnerability CVE-2026-21992 has received a CVSS score of 9.8, making it one of the most severe vulnerabilities discovered this year. The high score is due to the fact that the exploitation can be done without authentication, over a network, with low complexity and without user interaction. Attackers can achieve complete control of the system, affecting the confidentiality, integrity and availability of data. The combined effect of these factors makes the vulnerability particularly dangerous for organizations that expose their systems to the Internet.

See also: CISA: Oracle Identity Manager Vulnerability in KEV Catalog

Oracle CVE-2026-21992 vulnerability Identity Manager remote code execution

According to advisory , the vulnerability affects the REST WebServices component of Identity Manager and the Web Services Security component of Web Services Manager.

Oracle Identity Manager is responsible for identity and access management in enterprise environments, while Oracle Web Services Manager is a policy-driven framework for managing and securing web services. These products are critical components of Oracle 's Fusion Middleware infrastructure and are widely used in enterprise environments for user management and service security.

Oracle: Protection and Risk Management Strategies

To best protect against this vulnerability, organizations should adopt a layered security approach. First, Web Application Firewalls (WAF) can provide temporary protection until updates are installed. Second, implementing strict network rules and using VPNs to access management interfaces can reduce the attack surface. Third, continuously monitoring logs for suspicious activity in REST WebServices is critical for early detection of exploitation attempts.

See also: CISA: Microsoft Configuration Manager Vulnerability in KEV Catalog

Oracle Identity Manager critical security vulnerability CVE-2026-21992

Oracle strongly recommends that you apply available security updates promptly for optimal protection.

Additionally, system administrators should restrict network access to affected HTTP endpoints and monitor for exploitation attempts.

See also: SpyCloud's Identity Exposure 2026 Report: Theft Explosion

The emergency nature of this update highlights the ongoing threat facing identity management systems and the importance of proactive security. Organizations should keep their systems up to date. Developing a comprehensive vulnerability management plan and regularly assessing the security of systems is essential to maintaining a strong level of protection. SecurityWeek reports that similar vulnerabilities continue to be a target for cyberattackers worldwide, making immediate action more critical than ever.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS