CVE-2026-21992: Critical Out-of-Band Oracle Identity Manager and Oracle Web Services Manager Remote Code Execution Vulnerability
2026-03-20T20:52:24Z•f6299314c8d694ace2b07fced589b1a6b49bec3d5dbac7b87ee950611aa3cf38
appseccnappexposure-managementiranian-actorsmicrosoft-wordn-daynerc-cip-complianceole-bypassoperation-epic-furyoracleoracle-identity-manageroracle-web-services-managerout-of-bandremote-code-executiontenable-research
What happened
Tenable published multiple security advisories and analyses: an out-of-band Oracle alert for CVE-2026-21992 — a critical (CVSSv3 9.8) unauthenticated RCE in Oracle Identity Manager and Oracle Web Services Manager (Oracle issued the alert outside its regular CPU cycle); the advisory notes a related exploited flaw CVE-2025-61757. Tenable also reported a high-impact Microsoft Word OLE/Mark-of-the-Web bypass (CVE-2026-21514) affecting ~14 million assets and urged immediate patching and mitigations. Additional Tenable research covers exposure-management recommendations, Operation Epic Fury analysis
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- f6299314c8d694ace2b07fced589b1a6b49bec3d5dbac7b87ee950611aa3cf38
- Enrichment time
- 2026-03-20T20:52:24Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.