Find notable cyber news and cases, enriched with sources, timelines, and signals.
Exploitation Wave Campaign ×2 Security Patch Release ×2 Vulnerability

Oracle E-Business Suite CVE-2025-61882 exploitation, extortion, and breach fallout

Updated 21.09.2026 15:30
Case score 65
Members 6 First seen 06.10.2025 04:37 Latest activity 21.09.2026 15:30

Overview

**Oracle E-Business Suite** exposure around **CVE-2025-61882** developed from zero-day exploitation into sustained data theft and extortion, with later victim disclosures showing concrete fallout. Available material places intrusion activity by **August 9, 2025**, extortion outreach from **September 29**, and a broader technical picture that also includes exploitation activity around **CVE-2025-61884**. Oracle issued emergency fixes for both flaws and **CISA** set KEV deadlines, but organizations with historical internet exposure still need compromise review because theft and coercion were already underway before patching.
Latest development Open development history 6 earlier developments Harvard University linked to Oracle E-Business Suite zero-day breach Harvard University is investigating a data breach tied to Oracle E-Business Suite CVE-2025-61882 after Clop added Harvard to its data leak site and said it would release the university’s data; Harvard said the affected activity appears limited to a small administrative unit, that it applied Oracle’s patch to remediate the vulnerability, and that it has no evidence of compromise to other University systems.
  1. Earlier development

    ShinyHunters defaces Clop's Tor leak site

    ShinyHunters defaced Clop's Tor leak site after exploiting an alleged unauthenticated file upload vulnerability in Grav CMS, uploading a text file with a warning and later claiming full access to the server, source code, Grav CMS plugins, system logs, /var/log files, and the onion private keys; the group said the move was retaliation tied to Clop's 2025 Oracle E-Business Suite data theft campaign and threatened to extort Clop within 72 hours.

  2. Earlier development

    Harvard University confirmed as Oracle EBS campaign victim

    Harvard University was listed on the Cl0p data leak website on October 12, and the cybercriminals later published a link to data allegedly stolen from Harvard. Harvard confirmed it was targeted in the Oracle EBS campaign and said the impact appears limited to a small administrative unit, while GTIG and Mandiant said dozens of organizations have been targeted.

  3. Earlier development

    Oracle discloses CVE-2025-61882 and publishes leaked IOC

    Oracle discloses CVE-2025-61882, lists the leaked proof-of-concept as an IOC, and says the separate /OA_HTML/SyncServlet exploit path was fixed with mod_security rules and by stubbing out the SYNCSERVLET class.

  4. Earlier development

    CrowdStrike and Mandiant separate two Oracle E-Business Suite campaigns

    CrowdStrike and Mandiant say Oracle E-Business Suite was targeted in two distinct campaigns: a July campaign that used an SSRF exploit against the "/configurator/UiServlet" endpoint now confirmed as CVE-2025-61884, and an August campaign that used a different exploit against the "/OA_HTML/SyncServlet" endpoint and was fixed under CVE-2025-61882, which is attributed to Clop.

  5. Earlier development

    Clop Oracle E-Business Suite extortion campaign

    The campaign began its extortion phase when **Oracle E-Business Suite** ransom emails started reaching **multiple companies**. The opening demand centered on alleged stolen files and a threat to leak the data unless payment was made.

  6. Earlier development

    First known Oracle E-Business Suite exploitation on August 9, 2025

    CrowdStrike identified the first known exploitation of CVE-2025-61882 in Oracle E-Business Suite on August 9, 2025, marking the start of the abuse pattern tied to Graceful Spider (aka Cl0p). The flaw is a critical unauthenticated remote code execution vulnerability in exposed Oracle EBS environments.

Signals

Impact signals
Exploitation
Affected impact
CVEs/products
Geographic context
Remediation
Status
Threat context

Threat actor context

11 listed

Malware & tooling context

6 families · 5 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Exploitation Wave Oracle E-Business Suite Cl0p multi-vulnerability exploitation wave
Updated 07.10.2025 08:12 Lead Contribution 65
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

**Oracle E-Business Suite (EBS)** exploitation tied to **Clop / FIN11** has been ongoing since at least **August 9, 2025**, with **CVE-2025-61882** used for **unauthenticated remote code execution** and **data theft**. **Google Threat Intelligence Group (GTIG)** and **Mandiant** said the campaign likely exfiltrated a **significant amount** of data, and that extortion emails sent since **September 29** referenced contact addresses **[email protected]** and **[email protected]**. **Oracle** released an emergency patch on **October 4** for affected **12.2.3-12.2.14** versions, and GTIG said patched servers are likely no longer vulnerable to known exploitation chains.

Campaign Clop Oracle E-Business Suite extortion campaign
Updated 06.10.2025 04:37 Scoring Support
Objective Financial Extortion Campaign Active

**Clop**'s **Oracle E-Business Suite** extortion campaign has expanded from ransom emails to named victims and leak-site pressure, with **LKQ** among the first victims listed and the activity linked to **CVE-2025-61882**. **Mandiant** and **Google Threat Intelligence Group** tracked the campaign after companies received emails claiming data theft from their EBS systems, and **Oracle** told customers to install the latest **Critical Patch Updates** after saying Clop was exploiting an EBS flaw patched in **July 2025**. In a separate but related development, **ShinyHunters** says its breach of Clop's **Tor leak site** was retaliation tied to the same campaign and claims it stole server data, **/var/log** files, and the onion service private keys, though only the defacement and uploaded file were independently confirmed. **Harvard University** was also listed on Clop's leak site and said its impact appears limited to a small administrative unit, while the broader campaign has targeted **more than 100 organizations** across multiple sectors.

Vulnerability Oracle E-Business Suite actively exploited unauthenticated RCE (CVE-2025-61882)
Updated 06.10.2025 04:37 Scoring Support
Exploitation Active Exploitation Exploit Public Exploit Data Type Physical Addresses CVSS 9.8 Critical 1 more in details
All signals
Exploitation Active Exploitation Exploit Public Exploit Data Type Physical Addresses CVSS 9.8 Critical Patch Patch Available

**CVE-2025-61882** is a critical **Oracle E-Business Suite** vulnerability in **Oracle Concurrent Processing / BI Publisher Integration** that enabled **unauthenticated remote code execution** and was patched by Oracle on **October 4, 2025**. Oracle said the issue affects **versions 12.2.3–12.2.14**, published **indicators of compromise**, and tied the flaw to **Clop** data theft activity that began in **August 2025**. A later update linked **Harvard University** to the campaign after Clop added it to a leak site; Harvard said the activity appears limited to a **small administrative unit**, it applied Oracle’s patch, and it has **no evidence of compromise** to other university systems. **Estée Lauder** also disclosed that its **Oracle E-Business Suite** used for **HR management** was intruded on **or around August 9, 2025**, and that an unauthorized party obtained **personal information of certain individuals**.

Campaign Oracle E-Business Suite dual-endpoint exploit campaigns
Updated 21.10.2025 22:15 Scoring Support
Objective Financial Extortion Campaign Attributed Patch Patch Available

Two **Oracle E-Business Suite** exploit campaigns hit separate endpoints in **July and August 2025**, expanding the risk to exposed enterprise instances. The activity matters because the attackers used **different attack paths**, showing sustained targeting rather than a one-off flaw. One phase mapped to **CVE-2025-61884** and the other to **CVE-2025-61882**, with the latter attributed to the **Clop ransomware gang**.

Security Patch Release Oracle E-Business Suite CVE-2025-61884 emergency security update
Updated 13.10.2025 17:42 Context
Exploitation No Known Exploitation CVSS 7.5 High Urgency High Patch Patch Available

**Oracle E-Business Suite** **CVE-2025-61884** is an **unauthenticated SSRF** flaw in the **Oracle Configurator runtime** that **CISA** says is being **actively exploited**. Oracle disclosed the issue on **October 11**, rated it **CVSS 7.5**, and told federal agencies to patch by **November 10, 2025**. Reporting ties the abuse to **July attacks** and a leaked exploit associated with **ShinyHunters** and the **Scattered Lapsus$** extortion group, while separating it from the distinct **CVE-2025-61882** activity against **/OA_HTML/SyncServlet** attributed to **Clop**.

Security Patch Release Oracle security patch release for CVE-2025-61882
Updated 06.10.2025 08:15 Context
Exploitation Active Exploitation CVSS 9.8 Critical Urgency Immediate Patch Patch Available

**Oracle** released an **emergency update** for **Oracle E-Business Suite** to fix **CVE-2025-61882**, a **critical** flaw with **active exploitation** risk tied to **Cl0p data theft attacks**. The bug can be reached over **HTTP without authentication** and may enable **remote code execution** in the **Oracle Concurrent Processing** component. Oracle also said it issued additional fixes after uncovering more potential exploitation during its investigation.