Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a critical vulnerability in Oracle Identity Manager, tracked as CVE-2025-61757, is being actively exploited in the wild. This flaw allows unauthenticated remote code execution and has a CVSS score of 9.8, indicating...
A critical vulnerability in Oracle Identity Manager, tracked as CVE-2025-61757, allows remote code execution (RCE) without authentication. Discovered by Searchlight Cyber researchers, the flaw has been actively exploited in attacks, prompting warnings from CISA for government agencies to apply the p...
A critical remote code execution vulnerability, tracked as CVE-2025-61757, has been identified in Oracle Identity Manager. This flaw allows unauthenticated attackers to execute code remotely and has been actively exploited in the wild, potentially as a zero-day. The vulnerability was disclosed and p...