CVE-2026-21992Patch(oracle / identity_manager)

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 49 mentions and remains active

Immediate actions

  • Patch oracle identity_manager systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager and Oracle Web Services Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager and Oracle Web Services Manager. Note: Oracle Web Services Manager is installed with an Oracle Fusion Middleware Infrastructure. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

7.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • identity_manager
  • web_services_manager

Threat summary

  • Active exploitation appears in 12 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 201 mentions across 24 observed days

What's happening

  • Active exploitation reported across 12 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 147 signals
  • Technical details provided in 169 signals
  • Disclosure: 39 classified signals
  • General: 13 classified signals
  • Peaked 22d ago at 49 mentions (2026-03-21); latest day: 2
  • 201 total mentions across 24 days

Affected systems

Vendors
Products
identity_managerweb_services_manager

2 versions affected across 2 products

Deep dive

Activity timeline201 mentions / 24d
012253749Mentions · 2026-03-20: 21Mentions · 2026-03-21: 49Mentions · 2026-03-22: 29Mentions · 2026-03-23: 37Mentions · 2026-03-24: 18Mentions · 2026-03-25: 9Mentions · 2026-03-26: 3Mentions · 2026-03-27: 8Mentions · 2026-03-28: 1Mentions · 2026-03-29: 2Mentions · 2026-03-30: 2Mentions · 2026-03-31: 3Mentions · 2026-04-01: 1Mentions · 2026-04-02: 1Mentions · 2026-04-14: 1Mentions · 2026-04-15: 7Mentions · 2026-04-20: 1Mentions · 2026-04-21: 1Mentions · 2026-05-07: 1Mentions · 2026-05-09: 1Mentions · 2026-05-11: 1Mentions · 2026-05-18: 1Mentions · 2026-06-19: 1Mentions · 2026-09-24: 2PoC Mentioned / Linked · 2026-03-21: 1Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-03-21: 2Active Exploitation · 2026-03-22: 1Active Exploitation · 2026-03-23: 4Active Exploitation · 2026-03-25: 1Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-03-30: 1Active Exploitation · 2026-04-15: 1Patch / Workaround · 2026-03-20: 8Patch / Workaround · 2026-03-21: 41Patch / Workaround · 2026-03-22: 22Patch / Workaround · 2026-03-23: 30Patch / Workaround · 2026-03-24: 14Patch / Workaround · 2026-03-25: 6Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-27: 8Patch / Workaround · 2026-03-29: 2Patch / Workaround · 2026-03-31: 2Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-15: 7Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-09: 1Patch / Workaround · 2026-05-18: 1Technical Details · 2026-03-20: 15Technical Details · 2026-03-21: 46Technical Details · 2026-03-22: 28Technical Details · 2026-03-23: 33Technical Details · 2026-03-24: 14Technical Details · 2026-03-25: 6Technical Details · 2026-03-26: 3Technical Details · 2026-03-27: 7Technical Details · 2026-03-28: 1Technical Details · 2026-03-29: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 4Technical Details · 2026-05-07: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-18: 1Technical Details · 2026-06-19: 1Technical Details · 2026-09-24: 203-2003-2203-2403-2603-2803-3004-0104-1404-2005-0705-1106-1909-24
Signal classification5 categories
Patch
13868.7%
Disclosure
3919.4%
General
136.5%
Active Exploitation
105.0%
PoC
10.5%
Referenced assets120 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-2021
Active Exploitation1Disclosure9General3Patch8
2026-03-2149
Active Exploitation2Disclosure3General2Patch41PoC1
2026-03-2229
Active Exploitation1Disclosure8Patch20
2026-03-2337
Active Exploitation3Disclosure5General3Patch26
2026-03-2418
Disclosure3General1Patch14
2026-03-259
Active Exploitation1Disclosure1General2Patch5
2026-03-263
Disclosure2Patch1
2026-03-278
Active Exploitation1Disclosure1Patch6
2026-03-281
Disclosure1
2026-03-292
Patch2
2026-03-302
Active Exploitation1General1
2026-03-313
General1Patch2
2026-04-011
Patch1
2026-04-021
Patch1
2026-04-141
Disclosure1
2026-04-157
Patch7
2026-04-201
Disclosure1
2026-04-211
Patch1
2026-05-071
Patch1
2026-05-091
Patch1
2026-05-111
Disclosure1
2026-05-181
Patch1
2026-06-191
Disclosure1
2026-09-242
Disclosure2
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Patch

    🚨 Oracle fixed a 9.8 “easily exploitable” RCE flaw in Identity Manager and Web Services Manager, allowing unauthenticated attackers to execute code over HTTP and take full control of systems. 🔗 Read → https://thehackernews.com/2026/03/oracle-patches-critical-cve-2026-21992.html

    Post summary

    Oracle released a patch for CVE‑2026‑21992, a high‑severity RCE affecting Identity Manager and Web Services Manager, after detailing its exploitation vector but providing no evidence of active exploitation.

    2383931612.6K
    1.1M followersView on X
  • Cyber Security News@The_Cyber_News
    Patch

    🛡️ Oracle Issues Security Update for Critical RCE Flaw in Identity Manager & Web Services Manager Source: https://cybersecuritynews.com/oracle-urgent-security-update/ Oracle has issued an out-of-band Security Alert addressing a critical remote code execution (RCE) vulnerability, CVE-2026-21992, affecting two widely deployed Fusion Middleware components, Oracle Identity Manager and Oracle Web Services Manager. CVE-2026-21992 is an unauthenticated, remotely exploitable flaw that requires no user interaction or special privileges to exploit. The attack vector is network-based with low complexity, meaning a threat actor only needs HTTP access to an exposed endpoint to potentially trigger remote code execution. #cybersecuritynews #oracle

    Post summary

    Oracle has released an urgent security update for CVE-2026-21992, a critical remote code execution flaw affecting Identity Manager and Web Services Manager, and users should apply the patch immediately.

    127169154.6K
    51.5K followersView on X
  • yousukezan@yousukezan
    Patch

    オラクル製品に認証不要で侵入される重大欠陥が見つかった。遠隔からの攻撃でシステム乗っ取りやコード実行が可能とされ、企業のID管理基盤が直接標的となる危険性がある。影響範囲は広く、ネットワーク越しに悪用できる点から早急な対応が求められている。 問題はCVE-2026-21992で、Oracle Identity ManagerおよびOracle Web Services Managerの特定バージョンに影響する。HTTP経由でアクセス可能な攻撃者が認証なしで侵入し、リモートコード実行やシステム完全掌握に至る恐れがあるとされる。NVDでも「容易に悪用可能」と評価されており、脆弱なインスタンスの乗っ取りにつながる危険性が指摘されている。現時点で実際の悪用は確認されていないが、Oracleは速やかなアップデート適用を強く推奨している。なお過去にはCVE-2025-61757が実際に悪用され、CISAの既知悪用脆弱性リストに追加された経緯もあり、同種の欠陥への警戒が必要とされる。 https://thehackernews.com/2026/03/oracle-patches-critical-cve-2026-21992.html

    Post summary

    The article announces a severe unauthenticated remote code execution flaw in Oracle Identity Manager and Web Services Manager, highlights the lack of demonstrated exploitation, and urges timely patching.

    0702533.0K
    12.1K followersView on X
  • Nicolas Krassas@Dinosn
    Patch

    Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager https://thehackernews.com/2026/03/oracle-patches-critical-cve-2026-21992.html

    Post summary

    The article announces that Oracle has released patches for CVE‑2026‑21992, a critical vulnerability that allows unauthenticated remote code execution in Oracle Identity Manager.

    2501852.5K
    153.4K followersView on X
  • Gray Hats@the_yellow_fall
    General

    Oracle warns of a critical 9.8 CVSS vulnerability (CVE-2026-21992) allowing unauthenticated attackers to take over Fusion Middleware and Identity Manager. #OracleSecurity #CVE202621992 #CyberSecurity #InfoSec #IdentityManagement #Vulnerability #PatchAlert https://securityonline.info/critical-9-8-cvss-flaw-exposes-oracle-identity-manager-cve-2026-21992/ https://t.co/WFE1LoDNiW

    Post summary

    Oracle reports CVE-2026-21992, a 9.8 CVSS vulnerability that allows unauthenticated attackers to take over Fusion Middleware and Identity Manager.

    070174794
    10.7K followersView on X
  • BleepingComputer@BleepinComputer
    General

    When asked whether CVE-2026-21992 was exploited in attacks, Oracle declined to comment. 🧐

    Post summary

    Oracle declined to comment on whether CVE-2026-21992 was exploited in attacks, and no further details about the vulnerability or its exploitation are provided.

    0401103.8K
    249.6K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Patch

    Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992) https://www.helpnetsecurity.com/2026/03/23/oracle-emergency-fix-cve-2026-21992/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    Oracle released an emergency patch for CVE‑2026‑21992, a pre‑authentication remote code execution vulnerability in Oracle Identity Manager.

    03071626
    193.8K followersView on X
  • Dr.Mashari@GMashari
    Patch

    📌 أوراكل تعالج ثغرة CVE-2026-21992: تنفيذ تعليمات برمجية عن بعد دون مصادقة 🛡️ الفئة: ثغرة 📝 الملخص: أصدرت أوراكل تحديثات أمنية لمعالجة ثغرة حرجة (CVE-2026-21992) تؤثر على منتجات Oracle Identity Manager و Oracle Web Services Manager. تُمكن هذه الثغرة من تنفيذ تعليمات برمجية عن بُعد (RCE) دون الحاجة للمصادقة، مما يشكل خطراً جسيماً على الأنظمة المستهدفة. يُنصح بشدة بتطبيق التحديثات الأمنية الصادرة من أوراكل فوراً لدرء الاستغلال المحتمل لهذه الثغرة. 🗓️ تاريخ النشر: 22/03/2026 🔗 للمزيد: https://thecyberthrone.in/2026/03/22/oracle-patches-cve-2026-21992-unauthenticated-rce/

    Post summary

    Oracle has released patches for CVE-2026-21992, a critical remote code execution vulnerability affecting Oracle Identity Manager and Web Services Manager, and urges users to apply them immediately.

    06040125
    9.0K followersView on X
  • HostingTech@HostingTechNet
    Patch

    Oracle Releases Emergency Patch CVE-2026-21992 https://hostingtech.net/oracle-releases-emergency-patch-cve-2026-21992/ via @HostingTech https://t.co/8fJExG8OLU

    Post summary

    Oracle has released an emergency patch for CVE-2026‑21992, as reported by HostingTech.

    00080204
    121 followersView on X
  • Alonso Palacios@alonsopalacio12
    Patch

    Oracle acaba de parchear CVE-2026-21992 (CVSS 9.8) que permitía RCE sin autenticación en Identity Manager. Mientras tanto, hackers tumbaron sistemas de alcoholímetros y dejaron conductores varados. La ciberseguridad está rota y nadie lo quiere admitir. https://t.co/3iG6jbzEFy

    Post summary

    Oracle has released a patch for a critical RCE vulnerability (CVE‑2026‑21992) in Identity Manager, while unrelated attacks on alcohol‑meter systems were also mentioned.

    70000117
    5 followersView on X
  • Pierluigi Paganini - Security Affairs@securityaffairs
    Patch

    #Oracle fixes critical RCE flaw CVE-2026-21992 in #Identity #Manager https://securityaffairs.com/189796/security/oracle-fixes-critical-rce-flaw-cve-2026-21992-in-identity-manager.html #securityaffairs #hacking

    Post summary

    Oracle has issued a fix for the critical remote-code-execution flaw CVE-2026-21992 affecting Oracle Identity Manager, as referenced in the linked article.

    01050288
    37.5K followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    🚨 𝐅𝐫𝐞𝐬𝐡 𝐂𝐕𝐄 𝐚𝐥𝐞𝐫𝐭 𝐣𝐮𝐬𝐭 𝐢𝐧! Uncover how CVE-2026-21992 enables unauthenticated RCE in Oracle Identity Manager and why rapid patching is critical for enterprise security right now. 🌐 Explore the write-up → https://www.purple-ops.io/cybersecurity-threat-intelligence-blog/cve-2026-21992-unauthenticated-rce/ We’d love to hear your perspective!

    Post summary

    The alert announces CVE‑2026‑21992, an unauthenticated RCE affecting Oracle Identity Manager, and urges immediate patching to mitigate the threat.

    3002097
    95 followersView on X
  • Lucas@lucasverdan
    Patch

    🛑 CVE-2026-21992: Oracle emergency patch for pre-auth RCE CVE-2026-21992 is a critical Oracle Identity Manager and Web Services Manager flaw. Oracle… 🔗 Details → https://invaders.ie/resources/blog/vulnerability/cve-2026-21992-oracle-emergency-patch-pre-auth-rce

    Post summary

    The tweet announces an Oracle emergency patch for CVE‑2026‑21992, detailing a critical pre‑authentication RCE flaw in Oracle Identity Manager and Web Services Manager.

    02020401
    307 followersView on X
  • Zyberwalls@ZyberWallS
    General

    Hackers don’t need your password anymore. CVE-2026-21992 lets them decide who gets access instead — by taking over your identity system itself. This is control, not intrusion. https://www.zyberwalls.com/2026/03/cve-2026-21992-oracle-identity-manager-rce.html #CyberSecurity #ZeroDay #IdentitySecurity #Infosec

    Post summary

    The post highlights CVE-2026-21992 as a remote code execution vulnerability that lets attackers compromise an Oracle identity system, but offers no Proof of Concept, exploit code, patch information, or evidence of active exploitation.

    0202052
    16 followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 أوراكل تسد ثغرة حرجة في Identity Manager أصدرت أوراكل تحديثات أمنية لمعالجة ثغرة أمنية حرجة (CVE-2026-21992) تؤثر على منتجات Identity Manager و Web Services Manager. تُمكن هذه الثغرة من تنفيذ تعليمات برمجية عن بُعد (RCE) دون الحاجة لمصادقة، مما يعرض الأنظمة المستهدفة لمخاطر بالغة. يُنصح بتطبيق التحديثات الأمنية الصادرة فوراً لتحصين الأنظمة ضد الاستغلال المحتمل. 🔗 للمزيد: https://thehackernews.com/2026/03/oracle-patches-critical-cve-2026-21992.html

    Post summary

    Oracle announced security patches for CVE‑2026‑21992, a critical RCE flaw in Identity Manager, and urged users to apply the updates immediately.

    01030737
    73 followersView on X
  • Tim!!@Vikktor_Tim
    Patch

    1. JUST SAW A BREAKING NEWS Oracle just dropped an emergency patch for a critical vulnerability in their Identity Manager. CVE-2026-21992 scores 9.8/10 and lets anyone run code on your system without even logging in. This one’s serious. Full breakdown thread 👇 #CyberSecurity https://t.co/UxDQn7yCDl

    Post summary

    Oracle released an emergency patch for CVE-2026-21992, a critical remote code execution vulnerability in Identity Manager, rated 9.8/10.

    2101097
    582 followersView on X
  • Mr.Rabbit@01ra66it
    Patch

    Oracleは、Identity ManagerとWeb Services Managerの未認証RCEであるCVE-2026-21992を緊急修正した。重要なのは、HTTP経由で認証なしに悪用でき、CVSS 9.8の最大級に近い深刻度で、通常の四半期CPUを待たずに臨時アラートが出た点。 影響を受けるのは Oracle Identity Manager と Oracle Web Services Manager の 12.2.1.4.0 と 14.1.2.1.0。Oracleは2026年3月19日にSecurity Alertを公開し、成功するとリモートコード実行に至ると説明している。NVDも、HTTP経由の未認証攻撃で両製品が侵害され得ると記載している。 APT: なし Malware: なし CVE: CVE-2026-21992 IoC: Oracle Identity Manager, Oracle Web Services Manager, REST WebServices, Web Services Security, unauthenticated HTTP RCE, versions 12.2.1.4.0 and 14.1.2.1.0 #CyberSecurity #ThreatIntel #Oracle #RCE #Vulnerability #CVE202621992 https://thehackernews.com/2026/03/oracle-patches-critical-cve-2026-21992.html

    Post summary

    Oracle issued an urgent patch for CVE‑2026‑21992, an unauthenticated HTTP RCE with CVSS 9.8, but no active exploitation or PoC details are reported.

    01012893
    3.4K followersView on X
  • Andre Gironda@AndreGironda
    Disclosure

    CVE-2026-21992 critical out-of-band Oracle Identity Manager and Oracle Web Services Manager remote code execution vulnerability -- https://www.tenable.com/blog/cve-2026-21992-critical-out-of-band-oracle-identity-manager-and-oracle-web-services-manager

    Post summary

    It announces CVE-2026-21992, a critical remote code execution vulnerability in Oracle Identity Manager and Oracle Web Services Manager.

    02020273
    3.6K followersView on X
  • CVE Official@CVE2026COIN
    Disclosure

    CVE-2026-21992 - Oracle Identity Manager / Oracle Web Services Manager - Affects Oracle Identity Manager and Oracle Web Services Manager. - Oracle says successful exploitation may result in remote code execution. - Oracle Security Alert released on 2026-03-20. - CVSS v3.1 Base Score: 9.8. Oracle directs customers to the Security Alert Advisory for detailed guidance.

    Post summary

    Oracle has disclosed CVE-2026-21992, a high‑severity (CVSS 9.8) remote code execution vulnerability in Oracle Identity Manager and Oracle Web Services Manager, and is directing customers to a security advisory for guidance.

    01020103
    21 followersView on X
  • キタきつね@foxbook
    Patch

    Oracle社、Identity Managerにおける認証前リモートコード実行の脆弱性(CVE-2026-21992)に対する緊急修正プログラムをリリース Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992) #HelpNetSecurity (Mar 23) https://www.helpnetsecurity.com/2026/03/23/oracle-emergency-fix-cve-2026-21992/

    Post summary

    Oracle has issued an emergency patch for a pre‑authentication remote code execution flaw (CVE‑2026‑21992) in its Identity Manager product. No proof‑of‑concept or active exploitation activity is reported in the text.

    00120263
    4.8K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Apporacleidentity_manager12.2.1.4.0--
Apporacleidentity_manager14.1.2.1.0--
Apporacleweb_services_manager12.2.1.4.0--
Apporacleweb_services_manager14.1.2.1.0--

Explore more