Oracle Security Update – 24 March 2026

Oracle has released a security update to fix a critical vulnerability affecting Oracle Identity Manager and Oracle Web Services Manager versions 12.2.1.4.0 and 14.1.2.1.0.

The addressed vulnerability could allow the remote attacker to execute arbitrary code without authentication and gain access to the affected systems.

Oracle Identity Manager and Oracle Web Services Manager Unauthenticated Remote Code Execution Vulnerability (CVE-2026-21992):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

It should be highlighted that Oracle is aware that the vulnerability “CVE-2026- 21992” is now being exploited in the wild.

Vulnerabilities

CVE-2026-21992

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Oracle Security Alert Advisory

References