Tag: Oracle

Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
News

Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager

A serious security vulnerability affecting Identity Manager and Web Services Manager that could be used to accomplish remote code execution has been fixed by Oracle through security patches. The vulnerability has a CVSS score of 9.8 out of a possible 10.0, and it is tagged as CVE-2026-21992. According to an Oracle alert, this vulnerability can be remotely exploited without authentication. This vulnerability could lead to remote code execution if it is successfully exploited. CVE-2026-21992 affects the following versions - Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 Oracle Web Services Manager versions 12.2.1.4.0 and 14.1.2.1.0 A description of the vulnerability in the NIST National Vulnerability Database (NVD) states that it is "easily exploitable" and m...
Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks
News

Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks

An urgent patch has been issued by Oracle to fix a serious security vulnerability in its E-Business Suite, which it claims was used in the most recent round of Cl0p data theft attacks. The vulnerability, known as CVE-2025-61882, has an undefined issue that could make it possible for an unauthenticated attacker with HTTP network access to infiltrate and take over the Oracle Concurrent Processing component. Oracle stated in a warning that this vulnerability can be remotely exploited without authentication, meaning that a username and password are not required to exploit it across a network. Remote code execution could occur if this vulnerability is effectively exploited. Oracle has provided remedies for CVE-2025-61882, according to a separate advisory from Rob Duhart, the company's...
Oracle customers confirm data stolen in alleged cloud breach is valid
News

Oracle customers confirm data stolen in alleged cloud breach is valid

Two malicious packages that are intended to infect another locally installed package have been found by cybersecurity experts on the npm registry, highlighting the ongoing development of software supply chain hacks that target the open-source community. Since its publication on March 15, 2025, the packages in question—ethers-provider2 and ethers-providerz—have been downloaded 73 times. No one downloaded the second package, which was probably deleted by the virus creator. In a study provided with The Hacker News, Lucija Valentić, a researcher from ReversingLabs, claimed that they were straightforward downloaders with a carefully concealed harmful payload. Their second stage, which would 'patch' the locally installed legitimate npm package ethers with a new file holding the malicio...
8220 Gang Behind ScrubCrypt Attack Targeting Oracle Weblogic Server
Risk, Security

8220 Gang Behind ScrubCrypt Attack Targeting Oracle Weblogic Server

A new payload that targets a vulnerable Oracle Weblogic Server in a specific Universal Resource Identifier has been linked to the threat actor known as "8220 Gang" (URI). The extraction of ScrubCrypt, a type of malware created to obfuscate and encrypt software with the objective of evading detection by security solutions, is what distinguishes the payload, according to Fortinet security researchers who researched it. In the advisory published on Wednesday, senior antivirus analyst Cara Lin from Fortinet stated, "We examined the malware introduced into a victim's machine and, as part of our examination read more 8220 Gang Behind ScrubCrypt Attack Targeting Oracle Weblogic Server. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our compreh...
CISA Alert: Oracle E-Business Suite and SugarCRM Vulnerabilities Under Attack
Risk, Security

CISA Alert: Oracle E-Business Suite and SugarCRM Vulnerabilities Under Attack

On February 2, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), citing evidence of active exploitation, added two security weaknesses to its Known Exploited Vulnerabilities (KEV) Catalog. The first of the two flaws is CVE-2022-21587 (CVSS score: 9.8), a serious problem affecting Oracle Web Applications Desktop Integrator versions 12.2.3 through 12.2.11. An unauthenticated attacker with network access via HTTP could compromise Oracle Web Applications Desktop Integrator by using a vulnerability in the Oracle E-Business Suite, according to CISA read the complete article Oracle E Business Suite and SugarCRM Vulnerabilities Under Attack. You can protect your business and yourself by keeping up with the latest cybersecurity news and articles with the help of reconbee.c...