Oracle patches zero-auth RCE in Identity Manager, Web Services Manager
No known exploitation yet, but unauthenticated remote code execution in government-deployed identity middleware makes this a patch-now item for federal asset owners.
TL;DR
Oracle released an out-of-band patch for CVE-2026-21992, a critical unauthenticated remote code execution vulnerability in Oracle Identity Manager and Oracle Web Services Manager versions 12.2.1.4.0 and 14.1.2.1.0. No active exploitation has been reported. Federal agencies, contractors, and MSPs running these Fusion Middleware products should patch immediately, identity management systems sit at the center of the authentication chain, and unauthenticated RCE there means an attacker can mint their own access.
Oracle shipped an out-of-band security alert for CVE-2026-21992, a remote code execution vulnerability in Oracle Identity Manager and Oracle Web Services Manager, both part of the Fusion Middleware stack. The affected versions are 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is exploitable over the network without authentication, an attacker who can reach the affected service can execute arbitrary code. Oracle's decision to issue an alert rather than wait for the next quarterly Critical Patch Update tells you how severe this is.
Oracle Identity Manager handles user provisioning, identity administration, and password management across enterprise environments. Oracle Web Services Manager is the security and policy enforcement layer for SOA and web services within Fusion Middleware. When the identity system itself is compromised without authentication, the attacker doesn't need to steal credentials. They can create accounts with full administrative rights, modify access policies, or pivot laterally through the middleware layer. For government agencies and defense contractors, where these products manage access to controlled systems and CUI environments, the blast radius is wide.
MS-ISAC reports no active exploitation as of the March 23 advisory date. That's the pre-exploitation window, and for unauthenticated RCE in widely deployed enterprise identity products, that window doesn't stay open long. The patch is available now from Oracle's security alert page. The testing-and-deploy cycle on this one is compressed, days, not weeks, between patch release and exploit development for this class of vulnerability.
For the practitioner Monday: inventory your Oracle Identity Manager and Web Services Manager instances, confirm whether you're running 12.2.1.4.0 or 14.1.2.1.0, apply the patch, and verify. If you're an MSSP managing these products for government clients, the same timeline applies across your customer base. For federal systems subject to CISA's BOD 22-01, this CVE isn't yet in the Known Exploited Vulnerabilities catalog, but the zero-auth entry point and the sensitivity of identity management infrastructure make it a strong candidate for inclusion.
Published ·Deep Fathom