Digital.Nhs.Uk
Oracle Identity Manager RCE Vulnerability Exploited in Active Attacks
First seen 23 Nov 2025, 12:25 UTC
•



+12
•50.7
Export
Article Content
Browse articles
A critical vulnerability in Oracle Identity Manager, tracked as CVE-2025-61757, allows remote code execution (RCE) without authentication. Discovered by Searchlight Cyber researchers, the flaw has been actively exploited in attacks, prompting warnings from CISA for government agencies to apply the patch released by Oracle on October 21, 2025.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Logitech Confirms Data Breach from Zero-Day Exploit by Clop Gang
Washington Post Confirms Breach from Oracle EBS Attacks by Cl0p Ransomware Gang
Cl0p Ransomware Group Claims Data Theft from Nearly 50 Companies
EU Sanctions Russia Over Ongoing Cyber Espionage Campaign
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure