Oracle disclosed three high-severity vulnerabilities in the Oracle Identity Manager Connector component of Oracle Fusion Middleware, tracked as CVE-2026-34285, CVE-2026-34286, and CVE-2026-34287. The flaws affect supported version 12.2.1.4.0 and are described as easily exploitable by unauthenticated attackers with network access over HTTPS, including issues in the product's Core component.
Successful exploitation could allow attackers to create, delete, or modify critical data and gain unauthorized access to sensitive information, including potentially complete access to all data reachable through the Oracle Identity Manager Connector. Oracle assigned each vulnerability a CVSS v3.1 score of 9.1, citing high confidentiality and integrity impact with no availability impact, and referenced the issues in its Critical Patch Update advisory.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Oracle disclosed CVE-2026-34285, CVE-2026-34286, and CVE-2026-34287 affecting Oracle Identity Manager Connector in Oracle Fusion Middleware version 12.2.1.4.0. The vulnerabilities were described as easily exploitable by unauthenticated attackers over HTTPS/network access and could allow unauthorized modification of critical data and access to connector-accessible data; each was rated CVSS 9.1.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcetenable.com
Open sourcetenable.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.