Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。用户已经提供了文章内容,所以我先仔细阅读一下。 文章主要讲的是Oracle发布了安全更新,修复了一个严重的安全漏洞CVE-2026-21992,CVSS评分高达9.8。这个漏洞影响了Identity Manager和Web Services Manager的某些版本,攻击者无需认证就能远程执行代码,导致系统被接管。虽然目前没有证据显示漏洞被利用,但Oracle建议用户尽快更新。 接下来,我需要将这些关键点浓缩到100字以内。首先确定主要信息:Oracle修复漏洞、漏洞影响的软件版本、CVSS评分、攻击方式、潜在风险以及建议措施。 然后组织语言,确保简洁明了。比如,“Oracle发布安全更新修复严重漏洞CVE-2026-21992”开头,接着说明影响范围和评分,“影响Identity Manager和Web Services Manager特定版本,CVSS评分9.8”。然后描述漏洞的危险性,“无需认证远程执行代码”,最后提到建议,“敦促用户立即更新以防范风险”。 检查字数是否在限制内,并确保没有使用任何开头模板。最终总结应该清晰传达所有重要信息。 </think> Oracle发布安全更新修复严重漏洞CVE-2026-21992,影响Identity Manager和Web Services Manager特定版本,CVSS评分9.8。该漏洞无需认证即可远程执行代码,可能导致系统被接管。Oracle敦促用户立即更新以防范风险。 2026-3-21 10:24:0 Author: thehackernews.com(查看原文) 阅读量:11 收藏

Vulnerability / Threat Intelligence

Oracle has released security updates to address a critical security flaw impacting Identity Manager and Web Services Manager that could be exploited to achieve remote code execution.

The vulnerability, tracked as CVE-2026-21992, carries a CVSS score of 9.8 out of a maximum of 10.0.

"This vulnerability is remotely exploitable without authentication," Oracle said in an advisory. "If successfully exploited, this vulnerability may result in remote code execution."

CVE-2026-21992 affects the following versions -

  • Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0
  • Oracle Web Services Manager versions 12.2.1.4.0 and 14.1.2.1.0

According to a description of the flaw in the NIST National Vulnerability Database (NVD), it's "easily exploitable" and could allow an unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager and Oracle Web Services Manager. This, in turn, can result in the successful takeover of susceptible instances.

Oracle makes no mention of the vulnerability being exploited in the wild. However, the tech giant has urged customers to apply the update without delay for optimal protection.

In November 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-61757 (CVSS score: 9.8), a pre-authenticated remote code execution flaw impacting Oracle Identity Manager, to the Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/03/oracle-patches-critical-cve-2026-21992.html
如有侵权请联系:admin#unsafe.sh