CVE-2026-21992: Critical Out-of-Band Oracle Identity Manager and Oracle Web Services Manager Remote Code Execution Vulnerability

2026-03-20T20:52:24Zf6299314c8d694ace2b07fced589b1a6b49bec3d5dbac7b87ee950611aa3cf38
appseccnappexposure-managementiranian-actorsmicrosoft-wordn-daynerc-cip-complianceole-bypassoperation-epic-furyoracleoracle-identity-manageroracle-web-services-managerout-of-bandremote-code-executiontenable-research

What happened

Tenable published multiple security advisories and analyses: an out-of-band Oracle alert for CVE-2026-21992 — a critical (CVSSv3 9.8) unauthenticated RCE in Oracle Identity Manager and Oracle Web Services Manager (Oracle issued the alert outside its regular CPU cycle); the advisory notes a related exploited flaw CVE-2025-61757. Tenable also reported a high-impact Microsoft Word OLE/Mark-of-the-Web bypass (CVE-2026-21514) affecting ~14 million assets and urged immediate patching and mitigations. Additional Tenable research covers exposure-management recommendations, Operation Epic Fury analysis

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
f6299314c8d694ace2b07fced589b1a6b49bec3d5dbac7b87ee950611aa3cf38
Enrichment time
2026-03-20T20:52:24Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.