CISA Orders Federal Agencies to Patch Oracle E-Business Suite Zero-Day
CONFIRMED90% CONFIDENCECISA's[1][2] alert of 'October 06, 2025' adds 'CVE-2025-61882 Oracle[4] E-Business Suite Unspecified Vulnerability'; the KEV catalog entry sets dateAdded 2025-10-06 and dueDate 2025-10-27 under BOD 22-01, which 'requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date'.
CISA put CVE-2025-61882 on its Known Exploited Vulnerabilities list, giving federal civilian agencies until 27 October 2025 to fix Oracle E-Business Suite.
1.00