The first entry is always the pin's source. Overall confidence is a weighted average of how firmly each reference supports the start and end times used above; a reference counts half as much for every 180 days older than the newest.
CISA's[2] alert of 'October 06, 2025' adds 'CVE-2025-61882 Oracle[4] E-Business Suite Unspecified Vulnerability'; the KEV catalog entry sets dateAdded 2025-10-06 and dueDate 2025-10-27 under BOD 22-01, which 'requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date'.
The catalog entry for CVE-2025-61882: dateAdded 2025-10-06, dueDate 2025-10-27, known ransomware campaign use 'Known'; CVE-2025-61884 added 2025-10-20, due 2025-11-10.[1]
CISA[1][2] then added CVE-2025-61884 and required agencies to patch it by 10 November 2025; recaps the two EBS campaigns.
Oracle's alert for the flaw CISA[1][2] listed: unauthenticated remote code execution in E-Business Suite 12.2.3-12.2.14.
Something missing or wrong? Say it in your own words: a link that backs this pin up, a different start or end date and why, or a fact it lacks or gets wrong. The AI checks it against this pin's sources, searches for better ones, and adds any page that backs you up. The pin's own sources still count most.