PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60992 Oracle CVE debrief

The CVE-2026-60992 vulnerability is in the Oracle Identity Manager Connector product of Oracle Fusion Middleware, specifically in the Core component. This vulnerability allows an unauthenticated attacker with network access via TLS to compromise Oracle Identity Manager Connector, potentially leading to takeover. The affected versions are 12.2.1.4.0 and 14.1.2.1.0. The CVSS score is 8.1, indicating high severity. Oracle Identity Manager Connector users should review and apply security patches, implement compensating controls, and verify inventory of instances and their versions.

Vendor
Oracle
Product
Identity Manager Connector
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-08-21
Advisory published
2026-08-18
Advisory updated
2026-08-21

Who should care

Oracle Identity Manager Connector users, administrators of Oracle Fusion Middleware, and security teams responsible for vulnerability management and patching should be aware of this vulnerability. They should review and apply security patches, implement compensating controls, and verify inventory of Oracle Identity Manager Connector instances and their versions. Additionally, they should consider vulnerability scanning and exception tracking for Oracle Fusion Middleware components. Security teams should prioritize patching and mitigation efforts based on the CVSS score of 8.1 and the potential for takeover of Oracle Identity Manager Connector. IT operations teams should verify the inventory of affected components and plan for patching through normal change control processes. Compliance and risk management teams should ensure that appropriate measures are taken to mitigate the risk associated with this vulnerability. Communication and coordination among these teams are crucial to ensure effective mitigation and minimize potential impact on the organization. Suppliers and third-party vendors who may have access to or interact with Oracle Identity Manager Connector should also be informed and take necessary precautions. Managed Security Service Providers (MSSPs) and incident response teams should be prepared to detect and respond to potential exploitation attempts. In summary, a broad range of stakeholders across IT, security, compliance, and risk management should be engaged to address this high-severity vulnerability effectively. The communication plan should include regular updates on patching progress, vulnerability status, and any changes in the threat landscape. Key performance indicators (KPIs) should be established to measure the effectiveness of mitigation efforts and ensure that all necessary actions are completed within the defined timelines. By taking a coordinated approach, organizations can minimize the risk associated with CVE-2026-60992 and protect their Oracle Identity Manager Connector deployments from potential exploitation. This multi-stakeholder approach will help ensure that the vulnerability is addressed comprehensively and that the risk of a

Technical summary

The vulnerability in Oracle Identity Manager Connector (component: Core) allows an unauthenticated attacker with network access via TLS to compromise the connector, potentially leading to takeover. Affected versions are 12.2.1.4.0 and 14.1.2.1.0. The CVSS score is 8.1, indicating high severity. The vulnerability can be exploited through TLS, and successful attacks can result in takeover of Oracle Identity Manager Connector. Users should review and apply Oracle's security patches for affected versions and implement compensating controls.

Defensive priority

High priority due to the CVSS score of 8.1 and potential for takeover of Oracle Identity Manager Connector.

Recommended defensive actions

  • Review and apply Oracle's security patches for affected versions of Oracle Identity Manager Connector.
  • Implement compensating controls such as network access restrictions and monitoring.
  • Verify inventory of Oracle Identity Manager Connector instances and their versions.
  • Consider vulnerability scanning and exception tracking for Oracle Fusion Middleware components.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability is in the Oracle Identity Manager Connector product of Oracle Fusion Middleware, specifically in the Core component. Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. The vulnerability allows an unauthenticated attacker with network access via TLS to compromise Oracle Identity Manager Connector, potentially leading to takeover.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:50.797Z and has not been modified since then.