Oracle Releases Emergency Patch for Critical Identity Manager Vulnerability
2026-03-23T07:24:03Z•f11bd13cf9135d73f56e2a2f7a9db007ac836c6fd4589c16efb2b24895d54075
cellular securitycve-2025-32975cve-2026-21992data breacheclypsiumeducation sectoremergency patchexploited in the wildhandalaidentity managerirankacemagento defacementnaviaoraclequestransomwareremote code executionsupply chain securityunauthenticated
What happened
Oracle released an emergency patch for a critical unauthenticated remote code execution vulnerability in Identity Manager (CVE-2026-21992) that may have been exploited in the wild. SecurityWeek also reports a potentially exploited Quest KACE vulnerability (CVE-2025-32975) affecting the education sector. Other notable stories this week include a large Navia data breach impacting ~2.7M, an ongoing Magento site defacement campaign, US takedown linking Handala to the Iranian government, mentions of KVM/Claude vulnerabilities and the Gentlemen ransomware group, and industry funding/news (Eclypsium,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- f11bd13cf9135d73f56e2a2f7a9db007ac836c6fd4589c16efb2b24895d54075
- Enrichment time
- 2026-03-23T07:24:03Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.