Find notable cyber news and cases, enriched with sources, timelines, and signals.
Exploitation Wave Campaign ×2 Security Patch Release ×2 Vulnerability

Oracle E-Business Suite CVE-2025-61882 exploitation, extortion, and breach fallout

Updated 23.12.2025 18:00
Case score 71
Members 6 First seen 06.10.2025 04:37 Latest activity 23.12.2025 18:00

Overview

**Oracle E-Business Suite** exposure around **CVE-2025-61882** has developed from zero-day disclosure into a broader exploitation and extortion story with confirmed breach fallout at universities. Available material ties active abuse to **Clop / Graceful Spider / FIN11**, with intrusions likely starting by **August 9, 2025**, executive extortion emails appearing from **September 29**, and separate reporting on a second exploited flaw, **CVE-2025-61884**. **University of Phoenix** disclosed a breach affecting **3,489,274 individuals**, while **Harvard University** said related activity appears limited to a small administrative unit. Oracle has issued emergency updates for both flaws, and **CISA** set KEV deadlines of **October 27, 2025** for **CVE-2025-61882** and **November 10, 2025** for **CVE-2025-61884**.
Latest development Open development history 4 earlier developments Harvard University confirmed as Oracle EBS campaign victim Harvard University was listed on the Cl0p data leak website on October 12, and the cybercriminals later published a link to data allegedly stolen from Harvard. Harvard confirmed it was targeted in the Oracle EBS campaign and said the impact appears limited to a small administrative unit, while GTIG and Mandiant said dozens of organizations have been targeted.
  1. Earlier development

    GTIG links Oracle EBS extortion campaign to Clop/FIN11

    Google Threat Intelligence Group and Mandiant said Clop/FIN11 likely began targeting Oracle E-Business Suite instances as early as August 9, 2025 and later used extortion emails sent since September 29 to executives at several organizations, including messages tied to [email protected] and [email protected]. The researchers said the campaign followed months of intrusion activity, that CVE-2025-61882 exploitation began before patches were available, and that the threat actor had already exfiltrated a significant amount of Oracle EBS data.

  2. Earlier development

    Oracle discloses CVE-2025-61882 and publishes leaked IOC

    Oracle discloses CVE-2025-61882, lists the leaked proof-of-concept as an IOC, and says the separate /OA_HTML/SyncServlet exploit path was fixed with mod_security rules and by stubbing out the SYNCSERVLET class.

  3. Earlier development

    Clop Oracle E-Business Suite extortion campaign

    The campaign began its extortion phase when **Oracle E-Business Suite** ransom emails started reaching **multiple companies**. The opening demand centered on alleged stolen files and a threat to leak the data unless payment was made.

  4. Earlier development

    First known Oracle E-Business Suite exploitation on August 9, 2025

    CrowdStrike identified the first known exploitation of CVE-2025-61882 in Oracle E-Business Suite on August 9, 2025, marking the start of the abuse pattern tied to Graceful Spider (aka Cl0p). The flaw is a critical unauthenticated remote code execution vulnerability in exposed Oracle EBS environments.

Signals

Impact signals
Exploitation
Affected impact
CVEs/products
Geographic context
Remediation
Status
Threat context

Threat actor context

11 listed

Malware & tooling context

6 families · 5 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Exploitation Wave Oracle E-Business Suite Cl0p multi-vulnerability exploitation wave
Updated 07.10.2025 08:12 Lead Contribution 65
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

**Oracle E-Business Suite (EBS)** exploitation tied to **Clop / FIN11** has been ongoing since at least **August 9, 2025**, with **CVE-2025-61882** used for **unauthenticated remote code execution** and **data theft**. **Google Threat Intelligence Group (GTIG)** and **Mandiant** said the campaign likely exfiltrated a **significant amount** of data, and that extortion emails sent since **September 29** referenced contact addresses **[email protected]** and **[email protected]**. **Oracle** released an emergency patch on **October 4** for affected **12.2.3-12.2.14** versions, and GTIG said patched servers are likely no longer vulnerable to known exploitation chains.

Campaign Clop Oracle E-Business Suite extortion campaign
Updated 06.10.2025 04:37 Scoring Support Contribution 1
Objective Financial Extortion Campaign Active

**Clop**'s **Oracle E-Business Suite** extortion campaign has now been tied to **LKQ**, which was named by the group on its leak site as one of the first victims. The broader campaign is linked to **CVE-2025-61882** and has targeted **more than 100 organizations** across multiple sectors since it surfaced in **early October 2025**. In a separate disclosure, the **University of Phoenix** said attackers accessed its systems during **August 13-22, 2025** through its **Oracle E-Business Suite (EBS)** financial application. The university said the breach affected **3,489,274 individuals**, including **9131 Maine residents**, and involved sensitive personal and financial information.

Campaign Oracle E-Business Suite dual-endpoint exploit campaigns
Updated 21.10.2025 22:15 Scoring Support Contribution 1
Objective Financial Extortion Campaign Attributed Patch Patch Available

Two **Oracle E-Business Suite** exploit campaigns hit separate endpoints in **July and August 2025**, expanding the risk to exposed enterprise instances. The activity matters because the attackers used **different attack paths**, showing sustained targeting rather than a one-off flaw. One phase mapped to **CVE-2025-61884** and the other to **CVE-2025-61882**, with the latter attributed to the **Clop ransomware gang**.

Vulnerability Oracle E-Business Suite actively exploited unauthenticated RCE (CVE-2025-61882)
Updated 06.10.2025 04:37 Scoring Support
Exploitation Active Exploitation Exploit Public Exploit Data Type Physical Addresses CVSS 9.8 Critical 1 more in details
All signals
Exploitation Active Exploitation Exploit Public Exploit Data Type Physical Addresses CVSS 9.8 Critical Patch Patch Available

**Oracle** disclosed and patched **CVE-2025-61882**, a critical **Oracle E-Business Suite** zero-day in **Concurrent Processing / BI Publisher Integration** that enabled unauthenticated remote code execution and was tied to **Clop** data theft activity. Oracle said the flaw affected **12.2.3-12.2.14**, issued an emergency update, and published indicators of compromise after the abuse was linked to **August 2025**. On **Dec. 23, 2025**, **Harvard University** said Clop had added it to its leak site and threatened to release data. Harvard said the activity appeared limited to a small administrative unit and that it had applied Oracle's patch with no evidence of compromise to other university systems.

Security Patch Release Oracle E-Business Suite CVE-2025-61884 emergency security update
Updated 13.10.2025 17:42 Context
Exploitation No Known Exploitation CVSS 7.5 High Urgency High Patch Patch Available

**Oracle E-Business Suite** **CVE-2025-61884** is an **unauthenticated SSRF** flaw in the **Oracle Configurator runtime** that **CISA** says is being **actively exploited**. Oracle disclosed the issue on **October 11**, rated it **CVSS 7.5**, and told federal agencies to patch by **November 10, 2025**. Reporting ties the abuse to **July attacks** and a leaked exploit associated with **ShinyHunters** and the **Scattered Lapsus$** extortion group, while separating it from the distinct **CVE-2025-61882** activity against **/OA_HTML/SyncServlet** attributed to **Clop**.

Security Patch Release Oracle security patch release for CVE-2025-61882
Updated 06.10.2025 08:15 Context
Exploitation Active Exploitation CVSS 9.8 Critical Urgency Immediate Patch Patch Available

**Oracle** released an **emergency update** for **Oracle E-Business Suite** to fix **CVE-2025-61882**, a **critical** flaw with **active exploitation** risk tied to **Cl0p data theft attacks**. The bug can be reached over **HTTP without authentication** and may enable **remote code execution** in the **Oracle Concurrent Processing** component. Oracle also said it issued additional fixes after uncovering more potential exploitation during its investigation.