Scmagazine Critical Oracle Identity Manager RCE Vulnerability Exploited
Article Content
Browse articles
A critical remote code execution vulnerability, tracked as CVE-2025-61757, has been identified in Oracle Identity Manager. This flaw allows unauthenticated attackers to execute code remotely and has been actively exploited in the wild, potentially as a zero-day. The vulnerability was disclosed and patched by Oracle on October 21, 2025, and has a CVSS score of 9.8.
Ask AI about this cluster
Answers cite the sources they use
Updated 183d ago How this analysis works
More articles in this cluster (4)
Following this threat?
Track Oracle and CVE-2025-4581 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
Critical OVERPASS Vulnerability in SAP Kernel Requires Immediate Action On September 8, 2026, SAP released security updates addressing 20 vulnerabilities, including a critical memory corruption flaw tracked as CVE-2026-44756, named OVERPASS. This vulnerability allows unauthenticated attackers to execute arbitrary commands on vulnerable SAP systems, leading to full compromise of business…