A critical vulnerability, CVE-2025-61757, has been identified in Oracle Fusion Middleware's Identity Manager component, allowing remote, unauthenticated attackers to achieve arbitrary remote code execution. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation and urging all organizations, especially those in the federal sector, to prioritize remediation. The affected versions include Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0, and exploitation could result in complete system compromise.
Security researchers recommend immediate upgrades to patched versions to mitigate risk. Tools such as runZero can assist organizations in identifying vulnerable Oracle Identity Manager installations using queries like vendor:="Oracle" product:="Identity Manager". CISA's Binding Operational Directive 22-01 mandates federal agencies to remediate KEV-listed vulnerabilities by specified deadlines, but all organizations are strongly encouraged to address this critical issue promptly to reduce exposure to active threats.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
Under Binding Operational Directive 22-01, CISA required Federal Civilian Executive Branch agencies to patch or otherwise remediate the KEV-listed Oracle Identity Manager vulnerability by 2025-12-12.
On 2025-11-21, CISA added CVE-2025-61757 to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. The agency identified it as an Oracle Fusion Middleware missing-authentication flaw posing significant risk.
Searchlight Cyber publicly released technical details and a proof-of-concept exploit for CVE-2025-61757, showing how crafted requests such as '.wadl' or related URI manipulation can bypass authentication and reach code-execution functionality.
Oracle disclosed and fixed CVE-2025-61757 on 2025-10-21 as part of its October 2025 Critical Patch Update. The critical flaw affects Oracle Identity Manager and can allow unauthenticated remote code execution.
SANS Internet Storm Center observed traffic targeting the vulnerable Oracle Identity Manager endpoint between 2025-08-30 and 2025-09-09, suggesting reconnaissance and possible zero-day exploitation before a patch was available.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
9 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcecsoonline.com
Open sourcesocradar.io
Open sourcesecurityaffairs.com
Open sourcethecyberthrone.in
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcecisa.gov
Open sourcerunzero.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.