Oracle releases emergency patch for critical vulnerability in Identity Manager

Oracle releases emergency patch for critical vulnerability in Identity Manager

By Eduard Kovacs
Publication Date: 2026-03-23 05:34:00

Oracle released out-of-band updates on Friday to patch a critical vulnerability affecting its Identity Manager and Web Services Manager products.

Oracle Identity Manager is an enterprise identity governance platform that automates user provisioning, deprovisioning, and access management across applications and systems. Oracle Web Services Manager is a policy-driven framework for managing and protecting web services.

Oracle announced that the products that are part of the Fusion middleware suite are affected by CVE-2026-21992, a critical vulnerability that can be exploited by an unauthenticated attacker for remote code execution.

According to Oracle advisoryThe vulnerability has a CVSS score of 9.8 and affects the REST WebServices component of Identity Manager and the Web Services Security component of Web Services Manager.

“An easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle Identity Manager and Oracle…