A critical vulnerability in Oracle Identity Manager, identified as CVE-2025-61757 and rated 9.8 on the CVSS scale, is being actively exploited by threat actors. The flaw affects Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0, allowing unauthenticated attackers to remotely execute code via the Oracle REST Web Services component. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued warnings about ongoing exploitation, and researchers from Searchlight Cyber have detailed how attackers can bypass authentication by appending specific strings such as ?WSDL or ;.wadl to REST endpoints.
Organizations using affected Oracle Identity Manager versions are urged to apply the vendor's recent patches immediately to mitigate the risk of compromise. The vulnerability's active exploitation highlights the importance of timely patch management and monitoring for unusual activity on exposed Oracle REST Web Services endpoints. Security teams should review their systems for signs of unauthorized access and ensure that all mitigations recommended by Oracle and CISA are implemented without delay.

See which actors are running it and whether you're in range.
10 events from the most recent confirmed update back to the earliest known activity.
Campbell's dismissed its chief information security officer following a lawsuit and the emergence of leaked audio tied to the dispute.
The FBI warned of a surge in bank account takeover fraud schemes, saying reported losses had reached $262 million.
The FCC imposed a $1.5 million penalty on Comcast after a vendor breach exposed personally identifiable information of more than 237,000 subscribers.
Spanish airline Iberia disclosed a breach involving a third-party vendor, and the Everest Group claimed responsibility while attempting to extort the company.
A high-severity denial-of-service vulnerability was reported in Shelly Pro 4PM smart relays, adding to the week's notable product security issues.
Major cloud providers patched five critical vulnerabilities in the Fluent Bit log processor to reduce exposure for customers using affected components.
The Shai-Hulud 2.0 campaign compromised more than 600 npm packages, leaked thousands of secrets, and affected hundreds of organizations using advanced evasion and propagation techniques.
CISA issued urgent guidance directing organizations to patch CVE-2025-61757 after reports of active exploitation of the Oracle Identity Manager vulnerability.
Security reporting indicated that the recently patched Oracle Identity Manager flaw was already under active exploitation, increasing urgency for organizations to apply updates.
Oracle released a fix for CVE-2025-61757 in Oracle Identity Manager, a critical 9.8 CVSS vulnerability that allows unauthenticated remote code execution through REST Web Services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.