Oracle E-Business Suite CVE-2025-61882 exploitation, extortion, and breach fallout
Case score 65
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 65
- Main story score
- 65
- Related evidence lift
- +0 / 20
- Contributing updates
- 2
- Context updates
- 2
- Exploitation Wave Defines the ongoing Oracle EBS exploitation wave, timing, and disclosed victim fallout. main
- Vulnerability Defines CVE-2025-61882, affected versions, exploitation status, and concrete university breach fallout. main
- Security Patch Release Anchors the emergency fix and KEV response for CVE-2025-61884. context
- Security Patch Release Anchors the emergency fix and mitigation state for CVE-2025-61882. context
-
Old: Oracle E-Business Suite exploitation and extortion around CVE-2025-61882New: Oracle E-Business Suite CVE-2025-61882 exploitation, extortion, and breach falloutWhy old title changed: The previous title is too generic now that the scope includes confirmed breach fallout at universities alongside the exploitation and extortion activity.The new title keeps CVE-2025-61882 central while better reflecting the reader-facing story: active exploitation, extortion pressure, and confirmed downstream breach disclosures.
Overview
Latest development Open development history Harvard University linked to Oracle E-Business Suite zero-day breach Harvard University is investigating a data breach tied to Oracle E-Business Suite CVE-2025-61882 after Clop added Harvard to its data leak site and said it would release the university’s data; Harvard said the affected activity appears limited to a small administrative unit, that it applied Oracle’s patch to remediate the vulnerability, and that it has no evidence of compromise to other University systems.
-
ShinyHunters defaces Clop's Tor leak site
ShinyHunters defaced Clop's Tor leak site after exploiting an alleged unauthenticated file upload vulnerability in Grav CMS, uploading a text file with a warning and later claiming full access to the server, source code, Grav CMS plugins, system logs, /var/log files, and the onion private keys; the group said the move was retaliation tied to Clop's 2025 Oracle E-Business Suite data theft campaign and threatened to extort Clop within 72 hours.
-
Harvard University confirmed as Oracle EBS campaign victim
Harvard University was listed on the Cl0p data leak website on October 12, and the cybercriminals later published a link to data allegedly stolen from Harvard. Harvard confirmed it was targeted in the Oracle EBS campaign and said the impact appears limited to a small administrative unit, while GTIG and Mandiant said dozens of organizations have been targeted.
-
Oracle discloses CVE-2025-61882 and publishes leaked IOC
Oracle discloses CVE-2025-61882, lists the leaked proof-of-concept as an IOC, and says the separate /OA_HTML/SyncServlet exploit path was fixed with mod_security rules and by stubbing out the SYNCSERVLET class.
-
CrowdStrike and Mandiant separate two Oracle E-Business Suite campaigns
CrowdStrike and Mandiant say Oracle E-Business Suite was targeted in two distinct campaigns: a July campaign that used an SSRF exploit against the "/configurator/UiServlet" endpoint now confirmed as CVE-2025-61884, and an August campaign that used a different exploit against the "/OA_HTML/SyncServlet" endpoint and was fixed under CVE-2025-61882, which is attributed to Clop.
-
Clop Oracle E-Business Suite extortion campaign
The campaign began its extortion phase when **Oracle E-Business Suite** ransom emails started reaching **multiple companies**. The opening demand centered on alleged stolen files and a threat to leak the data unless payment was made.
-
First known Oracle E-Business Suite exploitation on August 9, 2025
CrowdStrike identified the first known exploitation of CVE-2025-61882 in Oracle E-Business Suite on August 9, 2025, marking the start of the abuse pattern tied to Graceful Spider (aka Cl0p). The flaw is a critical unauthenticated remote code execution vulnerability in exposed Oracle EBS environments.