Oracle pushes emergency fix for critical Identity Manager RCE flaw

2026-03-20T19:23:34Z8b4dacfcba768381b5810880a9002853b738e57079e03ce249e35075e459e008
apt28botnet-takedowncisaciscodata-breachemergency-patchincident-responselaw-enforcementmagentonaviaoperation-aliceoraclepatchingpolyshellremote-code-executionubiquitiunauthenticated-rceurgentvulnerabilityzimbra

What happened

Multiple high-impact security events reported: Oracle released an out-of-band emergency patch for an unauthenticated remote code execution vulnerability in Identity Manager and Web Services Manager (CVE-2026-21992). CISA ordered federal agencies to patch a maximum‑severity Cisco Secure Firewall Management Center flaw (CVE-2026-20131) by March 22. A new unauthenticated RCE dubbed “PolyShell” affects Magento Open Source/Adobe Commerce 2 (account takeover risk). Ubiquiti patched maximum‑severity UniFi flaws that may allow account takeover. Threat actor activity and takedowns include APT28 abusing

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
8b4dacfcba768381b5810880a9002853b738e57079e03ce249e35075e459e008
Enrichment time
2026-03-20T19:23:34Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.