Learn languages naturally with fresh, real content!

Popular Topics
Explore By Region
U.S. federal agencies must patch a critical Oracle Identity Manager flaw by Dec. 12 after it was found actively exploited.
CISA has ordered U.S. federal agencies to patch a critical, actively exploited vulnerability in Oracle Identity Manager (CVE-2025-61757) by December 12, adding it to its Known Exploited Vulnerabilities catalog.
The flaw, which allows unauthenticated remote code execution via a single HTTP request, was confirmed to be under active attack as early as August, with researchers calling the exploit "trivial."
Oracle issued a fix on October 21, but did not disclose evidence of exploitation at the time.
The vulnerability affects specific versions of Oracle Fusion Middleware and poses a severe risk due to its high CVSS score of 9.8.
CISA urges agencies to apply the October 21 patch or isolate affected systems from public networks.
Las agencias federales de EE.UU. deben parchear un fallo crítico de Oracle Identity Manager para el 12 de diciembre después de que se encontró explotado activamente.