Oracle pushes emergency fix for critical Identity Manager RCE flaw
2026-03-20T19:23:34Z•8b4dacfcba768381b5810880a9002853b738e57079e03ce249e35075e459e008
apt28botnet-takedowncisaciscodata-breachemergency-patchincident-responselaw-enforcementmagentonaviaoperation-aliceoraclepatchingpolyshellremote-code-executionubiquitiunauthenticated-rceurgentvulnerabilityzimbra
What happened
Multiple high-impact security events reported: Oracle released an out-of-band emergency patch for an unauthenticated remote code execution vulnerability in Identity Manager and Web Services Manager (CVE-2026-21992). CISA ordered federal agencies to patch a maximum‑severity Cisco Secure Firewall Management Center flaw (CVE-2026-20131) by March 22. A new unauthenticated RCE dubbed “PolyShell” affects Magento Open Source/Adobe Commerce 2 (account takeover risk). Ubiquiti patched maximum‑severity UniFi flaws that may allow account takeover. Threat actor activity and takedowns include APT28 abusing
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 8b4dacfcba768381b5810880a9002853b738e57079e03ce249e35075e459e008
- Enrichment time
- 2026-03-20T19:23:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.