- Start
- Oct 4, 202590% CONFIDENCEfrom the source
Oracle Issues Emergency Patch for E-Business Suite Zero-Day CVE-2025-61882
- On 4 October 2025 Oracle issued Security Alert CVE-2025-61882 for Oracle E-Business Suite 12.2.3 to 12.2.14, a flaw "remotely exploitable without authentication" that "may result in remote code execution"[1].
- The bug sits in Oracle Concurrent Processing (BI Publisher Integration) and scores 9.8 on CVSS 3.1; the October 2023 Critical Patch Update is a prerequisite for the fix, the alert lists indicators of compromise, and it credits CrowdStrike and Mandiant[1].
- Mandiant CTO Charles Carmakal said Clop exploited CVE-2025-61882 together with flaws patched in July to steal large amounts of data from victims in August 2025[5].
- CrowdStrike put the first known exploitation at 9 August 2025, and a proof-of-concept exploit had leaked online[3].
- CISA added the flaw to its Known Exploited Vulnerabilities catalog on 6 October[4], and Oracle followed with a second E-Business Suite alert, CVE-2025-61884 (CVSS 7.5, Configurator Runtime UI), on 11 October[2].
References 588% CONFIDENCE
The first entry is always the pin's source. Overall confidence is a weighted average of how firmly each reference supports the start and end times used above; a reference counts half as much for every 180 days older than the newest.
- [1]90%oracle.com/security-alerts/alert-cve-2025-61882.htmloracle.com· Posted Sep 24, 2026· Starts Oct 4, 2025 ✓· 49% of score
Oracle's[2] Security Alert Advisory CVE-2025-61882 lists '2025-October-04 Rev 1. Initial Release' in its modification history.
- [2]88%Oracle Security Alert Advisory - CVE-2025-61884oracle.com· Published Oct 11, 2025· 13% of score
Oracle's[1] second E-Business Suite alert, for a 7.5-rated Configurator Runtime UI flaw, released 11 October 2025.
- [3]84%Clop exploited Oracle zero-day for data theft since early Augustbleepingcomputer.com· Published Oct 7, 2025· 13% of score
CrowdStrike puts the first known exploitation at 9 August 2025; watchTowr found the leaked exploit is a chain needing a single HTTP request.[1]
- [4]90%CISA Adds Seven Known Exploited Vulnerabilities to Catalogcisa.gov· Published Oct 6, 2025· 13% of score
CISA added CVE-2025-61882 Oracle[1][2] E-Business Suite to its Known Exploited Vulnerabilities catalog on 6 October 2025.
- [5]85%Oracle patches EBS zero-day exploited in Clop data theft attacksbleepingcomputer.com· Published Oct 5, 2025· 13% of score
Reports the alert and Mandiant CTO Charles Carmakal's statement that Clop exploited CVE-2025-61882 and July-patched flaws to steal data in August 2025.[1]
Suggest a correction
Something missing or wrong? Say it in your own words: a link that backs this pin up, a different start or end date and why, or a fact it lacks or gets wrong. The AI checks it against this pin's sources, searches for better ones, and adds any page that backs you up. The pin's own sources still count most.