On March 20, 2026, Oracle disclosed a critical (CVSS score of 9.8) vulnerability ( CVE-2026-21992 ) impacting two Oracle Fusion Middleware components: Oracle Identity Manager and Oracle Web Services Manager. An unauthenticated attacker could exploit the vulnerability to obtain network access via HTTP and remotely execute code. Critical functions of the products are exposed due to the lack of network-level authentication. As of this publication, there are no reports of active exploitation.
Counter Threat Unit™ (CTU) researchers recommend that customers identify vulnerable components and apply the patches as appropriate in their environment.
The following protection developed by SophosLabs relates to this threat:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
