INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Oracle Fixes RCE Flaw in Identity Manager

| 2026-03-22 15:37 CRITICAL MEDIUM
Executive Summary AI-generated
The vulnerability, tracked as CVE-2026-21992 in Oracle Identity Manager and Web Services Manager, poses a significant threat to organizations relying on these systems. This critical security flaw allows unauthenticated attackers to over HTTP take control of the affected software, potentially leading to remote code execution and compromising system integrity. The vulnerability has been identified by SANS researcher Johannes B. Ullrich, who reported multiple HTTP POST attempts targeting the Oracle Identity Manager endpoint associated with CVE-2025-61757 in his organization's honeypot logs between August 30 and September 9, 2025. This suggests that exploitation of this flaw could occur weeks before an official patch is released by Oracle.
Technical Mitigations AI-generated
* Implement a secure authentication mechanism, such as OAuth or JWT-based authentication, to ensure that only authenticated users can access sensitive data and systems. * Regularly update and patch operating systems, applications, and services to prevent exploitation of known vulnerabilities like CVE-2026-21992. * Use network segmentation and firewalls to limit the spread of malware and unauthorized access within an organization's network. * Conduct regular security audits and penetration testing to identify potential vulnerabilities and weaknesses in Oracle Identity Manager and Web Services Manager.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-61757CVE-2025-61757 CVE-2026-21992CVE-2026-21992
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
September 9, 2025
Threat actors used a 556-byte POST payload to exploit a previously unknown zero-day vulnerability in Oracle Identity Manager.
organisation POST
data_breach 556 byte
organisation SecurityAffairs
October 2025
Oracle addressed the flaw with the release of Oracle Critical Patch Update Advisory – October 2025.
organisation Oracle Critical Patch Update Advisory
November 2025
Threat actors used an Oracle Fusion Middleware flaw to target versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Identity Manager in November 2025.
attribution CVE-2025-61757
tactic T1588.006 - Vulnerabilities
attribution KEV
vulnerability CVSS score of 9.8
attribution Oracle Fusion Middleware
attribution Known Exploited
tactic Remote Code Execution
general_metric 9.8 group
attribution the Known Exploited
infrastructure 12.2.1
infrastructure 4.0
infrastructure 14.1.2
infrastructure 1.0
2026-03-19
Threat actors used a vulnerability in Oracle's Identity Manager to gain unauthorized access.
March 19
Oracle released a security alert on March 19 to inform the public about a newly discovered critical Remote Code Execution (RCE) flaw in its Identity Manager software.
vulnerability CVE-2026-21992
2026-03-20
Threat actors exploited a previously unknown critical Remote Code Execution (RCE) vulnerability in Oracle's Identity Manager, identified as CVE-2026-21992.
vulnerability CVE-2026-21992
Mar 21, 2026
Threat actors used a known vulnerability in Oracle's Identity Manager to gain unauthorized access.
between August 30 and September 9, 2025
Threat actors used an exploit of a previously unknown vulnerability in Oracle Identity Manager to target the CVE-2025-61757 endpoint between August 30 and September 9, 2025.
organisation CVE-2025-61757
2026-03-22
Oracle fixed a critical severity flaw, CVE-2026-21992.
organisation Oracle
infrastructure 9.8
infrastructure 12.2.1
infrastructure 4.0
infrastructure 14.1.2
infrastructure 1.0
organisation CVSS
organisation CVE-2025-61757
organisation CVE-2026
organisation Cisco Drops
victims 2 Critical Large Organizations
organisation Identity
organisation RCE
organisation Oracle Patches Critical CVE-2026-21992
organisation Oracle Identity
organisation OIM
organisation OWSM
organisation the NIST National Vulnerability Database
organisation NVD
organisation REST WebServices
organisation Patch Update
organisation BleepingComputer
organisation The Red Report 2026
victims 1,000 organizations
organisation Oracle's
organisation Fusion Middleware Has Critical
organisation Fusion Middleware
organisation Walmart
organisation Huawei
organisation ExxonMobil
organisation Oracle Fusion Middleware Oracle
victims 10,000 employees
financial $1 employees
organisation API
organisation Misunderstood Risks Cause Cisco SD-WAN
Tactical Metrics
Metrics
infrastructure
​9.8
Software Version
Metrics
infrastructure
​12.2.1
Software Version
Metrics
infrastructure
​4.0
Software Version
Metrics
infrastructure
​14.1.2
Software Version
Metrics
infrastructure
​1.0
Software Version
Metrics
victims
1,000
Organizations
Metrics
victims
2
Critical Large Organizations
Metrics
victims
10,000
Employees
Metrics
financial
1,000,000,000
Employees
Metrics
data_breach
556
Byte