A critical vulnerability (CVE-2026-21992, CVSS 9.8) has been identified in core Oracle products. The specific attack vector and method are not detailed in the provided advisory. Affected versions include Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0, as well as Oracle Web Services Manager 12.2.1.4.0 and 14.1.2.1.0.
Categories: Threat Research Tags: advisory, vulnerability, Oracle