Oracle security patch release for CVE-2025-61757
Security Patch Release
Summary
Hide ▲
Show ▼
Oracle's October 2025 security updates fixed CVE-2025-61757 in Oracle Identity Manager, closing a pre-authentication RCE path that had already been exploited in attacks. The update was released on October 21, 2025. Because the flaw was potentially a zero-day, the patch was important for exposed Identity Manager deployments.
Related Happenings
Oracle E-Business Suite May 2026 Critical Security Patch Update (CVE-2026-46817)
Security Patch Release
H score53
First: 29.06.2026 16:46
Last: 29.06.2026 16:46
Sources 1
About this happening:
Oracle's May 2026 Critical Security Patch Update addressed CVE-2026-46817 in Oracle E-Business Suite, a critical flaw in Oracle Payments that could let an...
Oracle E-Business Suite May 2026 Critical Security Patch Update (CVE-2026-46817)
Security Patch ReleaseAbout this happening: Oracle's May 2026 Critical Security Patch Update addressed CVE-2026-46817 in Oracle E-Business Suite, a critical flaw in Oracle Payments that could let an...
Microsoft security patch release for CVE-2026-41089
Security Patch Release
H score43
First: 13.05.2026 00:46
Last: 13.05.2026 00:46
Sources 1
About this happening:
Microsoft and other major software vendors shipped a heavy May 2026 patch cycle, with fixes spanning Windows, iOS, Firefox, Oracle products, and Chrome...
Microsoft security patch release for CVE-2026-41089
Security Patch ReleaseAbout this happening: Microsoft and other major software vendors shipped a heavy May 2026 patch cycle, with fixes spanning Windows, iOS, Firefox, Oracle products, and Chrome...
Oracle security patch release for CVE-2026-21992
Security Patch Release
H score44
First: 21.03.2026 12:24
Last: 21.03.2026 12:24
Sources 1
About this happening:
Oracle released security updates for CVE-2026-21992, a critical flaw in Identity Manager and Web Services Manager that could enable unauthenticated remote co...
Oracle security patch release for CVE-2026-21992
Security Patch ReleaseAbout this happening: Oracle released security updates for CVE-2026-21992, a critical flaw in Identity Manager and Web Services Manager that could enable unauthenticated remote co...
Microsoft security patch release for CVE-2026-20805
Security Patch Release
H score42
First: 14.01.2026 02:47
Last: 14.01.2026 02:47
Sources 1
About this happening:
Microsoft released January 2026 security updates for Windows and supported software, fixing at least 113 vulnerabilities and 8 critical flaws. The release includes...
Microsoft security patch release for CVE-2026-20805
Security Patch ReleaseAbout this happening: Microsoft released January 2026 security updates for Windows and supported software, fixing at least 113 vulnerabilities and 8 critical flaws. The release includes...
Grafana Enterprise security update for CVE-2025-41115
Security Patch Release
H score41
First: 21.11.2025 17:40
Last: 21.11.2025 17:40
Sources 1
About this happening:
Grafana released security updates for CVE-2025-41115, a CVSS 10.0 flaw in Grafana Enterprise that could enable user impersonation or privilege escalation...
Grafana Enterprise security update for CVE-2025-41115
Security Patch ReleaseAbout this happening: Grafana released security updates for CVE-2025-41115, a CVSS 10.0 flaw in Grafana Enterprise that could enable user impersonation or privilege escalation...
Timeline
-
22.11.2025 01:50 2 articles · 7mo ago
Oracle releases October 2025 security updates for CVE-2025-61757
Mitigation Patch UpdateOracle released its October 2025 security updates on October 21, 2025, fixing CVE-2025-61757 in Oracle Identity Manager and closing the pre-authentication remote code execution path tied to the REST API authentication bypass and Groovy script compilation abuse.
Show sources
- CISA warns Oracle Identity Manager RCE flaw is being actively exploited — www.bleepingcomputer.com — 22.11.2025 01:50
- CISA warns Oracle Identity Manager RCE flaw is being actively exploited — www.bleepingcomputer.com — 22.11.2025 01:50
-
22.11.2025 01:50 1 articles · 7mo ago
CISA adds CVE-2025-61757 to the KEV catalog
Legal Policy Action UpdateOn November 21, 2025, CISA added CVE-2025-61757 in Oracle Identity Manager to the Known Exploited Vulnerabilities catalog and set a December 12 patch deadline for Federal Civilian Executive Branch agencies under Binding Operational Directive 22-01, citing active exploitation risk to the federal enterprise.
Show sources
- CISA warns Oracle Identity Manager RCE flaw is being actively exploited — www.bleepingcomputer.com — 22.11.2025 01:50
-
20.11.2025 02:00 1 articles · 7mo ago
Searchlight Cyber publishes exploit details for CVE-2025-61757
Technical Analysis UpdateOn November 20, 2025, Searchlight Cyber released a technical report on CVE-2025-61757 in Oracle Identity Manager, detailing the REST API authentication bypass that could expose protected endpoints via `?WSDL` or `;.wadl` and lead to pre-authentication remote code execution through the Groovy script compilation path; Johannes Ullrich also warned that the flaw may have been exploited as a zero-day as early as August 30, with accesses seen between August 30 and September 9.
Show sources
- CISA warns Oracle Identity Manager RCE flaw is being actively exploited — www.bleepingcomputer.com — 22.11.2025 01:50