Critical Vulnerability in Oracle Products
23 March 2026
Oracle has released security updates to address a critical vulnerability in Oracle Web Services Manager and Identity Manager. Users and administrators of affected products are advised to update to the latest versions immediately.
Background
Oracle has released security updates to address a critical vulnerability (CVE-2026-21992) in Oracle Web Services Manager and Identity Manager. The vulnerability has a Common Vulnerability Scoring System (CVSSv3.1) score of 9.8 out of 10.
Impact
The critical vulnerability bypasses authentication through remote exploitation over HTTP with low complexity and no user interaction, making exposed enterprise identity management and web services infrastructure highly susceptible to immediate compromise. Successful exploitation could allow a remote unauthenticated attacker to perform arbitrary code execution on affected systems.
Affected Products
The vulnerability affects Oracle Web Services Manager and Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0.
Mitigation
Users and administrators of affected products are advised to update to the latest versions immediately.
References
https://www.oracle.com/security-alerts/alert-cve-2026-21992.html
https://nvd.nist.gov/vuln/detail/CVE-2026-21992
https://thehackernews.com/2026/03/oracle-patches-critical-cve-2026-21992.html
