Critical Oracle Identity Manager RCE Vulnerability Exploited

Critical Oracle Identity Manager RCE Vulnerability Exploited

First seen 23 Nov 2025, 03:35 UTC ScmagazineScworldBleepingcomputerCybersecuritynews 87% similarity 50.7

Article Content

Browse articles
ThreatCluster

A critical remote code execution vulnerability, tracked as CVE-2025-61757, has been identified in Oracle Identity Manager. This flaw allows unauthenticated attackers to execute code remotely and has been actively exploited in the wild, potentially as a zero-day. The vulnerability was disclosed and patched by Oracle on October 21, 2025, and has a CVSS score of 9.8.

ThreatCluster AI

Community

Browse all →