CISA Orders Federal Agencies to Patch Oracle E-Business Suite Zero-Day
CONFIRMEDDate confidence: CONFIRMEDStated as firmHow firmly the source words the date: confirmed, scheduled, estimated, delayed or unverified.Show all CONFIRMED pins90% CONFIDENCEOverall confidence: 90%How well the pin's source and references back up its dates.Weighted average of how firmly 4 references, the source included, support the pin's start and end times; a reference counts half as much for every 180 days older than the newestShow all pins at 75% confidence or betterCISA's[1][2] alert of 'October 06, 2025' adds 'CVE-2025-61882 Oracle[4] E-Business Suite Unspecified Vulnerability'; the KEV catalog entry sets dateAdded 2025-10-06 and dueDate 2025-10-27 under BOD 22-01, which 'requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date'.
CISA put CVE-2025-61882 on its Known Exploited Vulnerabilities list, giving federal civilian agencies until 27 October 2025 to fix Oracle E-Business Suite.