Vulnerability Watch

Forum Discussion

scaveza's avatar
scaveza
Product Team
22 days ago

CVE-2026-21992: Critical Oracle Fusion Middleware Vulnerability Out-of-Band Security Alert

Oracle published an out-of-band security alert on March 19 for CVE-2026-21992, a critical remote code execution vulnerability affecting Oracle Identity Manager and Oracle Web Services Manager, both part of Oracle Fusion Middleware. The vulnerability has a CVSSv3 score of 9.8 and is remotely exploitable without authentication.

CVEDescriptionCVSSv3
CVE-2026-21992Oracle Identity Manager and Oracle Web Services Manager Remote Code Execution Vulnerability9.8

Out-of-band security alerts from Oracle are infrequent and signal elevated risk. Patches are available through Oracle's Fusion Middleware patch documentation.

For more information about the vulnerability, including the availability of patches and Tenable product coverage, please visit our blog.

No RepliesBe the first to reply