Story perspectives
Critical Oracle Vulnerability Exposed; Patch Urgently Required
11/22/2025
1 of 1
Story summary
- The Oracle Identity Manager vulnerability CVE-2025-61757 could allow remote code execution without authentication, risking full system compromise.
- Searchlight Cyber disclosed the flaw, which has a CVSS score of 9.8.
- Oracle patched the vulnerability in October 2025 and urged customers to apply the update promptly.
- Prior to the patch, suspicious activity from multiple IP addresses suggested exploitation attempts, with some activity linked to Searchlight Cyber's research.
