Exploitation Wave
Campaign ×2
Security Patch Release ×2
Vulnerability
Oracle E-Business Suite CVE-2025-61882 exploitation, extortion, and breach fallout
Updated 23.12.2025 18:00
Case score 71
Score breakdown
- Total
- 71
- Lead score
- 65
- Support bonus
- +6 / 20
- Scoring support
- 2
- Context members
- 2
Top contributors
- Exploitation Wave Defines the ongoing Oracle EBS exploitation wave, timing, and disclosed victim fallout. base
- Vulnerability Defines **CVE-2025-61882**, affected versions, exploitation status, and concrete university breach fallout. base
- Security Patch Release Anchors the emergency fix and KEV response for **CVE-2025-61884**. context
- Security Patch Release Anchors the emergency fix and mitigation state for **CVE-2025-61882**. context
Title history
-
Old: Oracle E-Business Suite exploitation and extortion around CVE-2025-61882New: Oracle E-Business Suite CVE-2025-61882 exploitation, extortion, and breach falloutWhy old title changed: The previous title is too generic now that the scope includes confirmed breach fallout at universities alongside the exploitation and extortion activity.The new title keeps **CVE-2025-61882** central while better reflecting the reader-facing story: active exploitation, extortion pressure, and confirmed downstream breach disclosures.
Case score 71
Members 6
Latest activity 23.12.2025 18:00
Active exploitation
Public PoC/exploit reported
KEV: CISA KEV
Patch available
Active exploitation
Public PoC/exploit reported
KEV: CISA KEV
Patch available
Members 6
First seen 06.10.2025 04:37
Last seen 21.10.2025 22:15
Updated 23.12.2025 18:00
Overview
**Oracle E-Business Suite** exposure around **CVE-2025-61882** has developed from zero-day disclosure into a broader exploitation and extortion story with confirmed breach fallout at universities. Available material ties active abuse to **Clop / Graceful Spider / FIN11**, with intrusions likely starting by **August 9, 2025**, executive extortion emails appearing from **September 29**, and separate reporting on a second exploited flaw, **CVE-2025-61884**.
**University of Phoenix** disclosed a breach affecting **3,489,274 individuals**, while **Harvard University** said related activity appears limited to a small administrative unit. Oracle has issued emergency updates for both flaws, and **CISA** set KEV deadlines of **October 27, 2025** for **CVE-2025-61882** and **November 10, 2025** for **CVE-2025-61884**.
A critical **Oracle E-Business Suite** zero-day, **CVE-2025-61882**, enabled unauthenticated remote code execution in affected **12.2.3-12.2.14** environments and became the main access path in ongoing data-theft and extortion activity. Available reporting places the intrusion activity as early as **August 9, 2025**, with significant data exfiltration occurring before patches were available and extortion emails reaching executives from **September 29** using **[email protected]** and **[email protected]**. The campaign has been linked in available material to **Clop / Graceful Spider / FIN11**, and disclosure activity later expanded into concrete victim fallout including a **University of Phoenix** breach affecting **3,489,274 individuals** and a **Harvard University** investigation that the school said appears limited to a small administrative unit.
Technical reporting describes abuse of **/OA_HTML/SyncServlet** and **Oracle's XML Publisher Template Manager** to upload and execute a malicious **XSLT** template, while separate July and August activity hit **/configurator/UiServlet** and helped bring **CVE-2025-61884** into scope as a second actively exploited Oracle EBS issue. That second flaw is an unauthenticated **SSRF** weakness in the **Oracle Configurator runtime** component, showing that defenders needed to review more than one endpoint and more than one exploitation chain across exposed EBS instances. Available evidence supports a sustained Oracle EBS intrusion-and-extortion sequence, but it does not establish the full victim count or prove that every reported intrusion used the same path.
Oracle released an emergency update for **CVE-2025-61882** on **October 4** and later issued an emergency out-of-band fix for **CVE-2025-61884**. Guidance tied to the first update indicates systems that received the fix are likely no longer vulnerable to known exploitation chains, but organizations with historical internet exposure still need compromise review because data theft and extortion were already underway before patching. **CISA** added both flaws to the **Known Exploited Vulnerabilities** catalog, setting remediation deadlines of **October 27, 2025** for **CVE-2025-61882** and **November 10, 2025** for **CVE-2025-61884**.