Oracle EBS zero-day exploitation wave (dozens of victims)
Exploitation Wave
Summary
Hide ▲
Show ▼
A multi-victim Oracle E-Business Suite (EBS) exploitation wave is affecting dozens of victims, with the total possibly exceeding 100. The activity is tied to zero-day vulnerabilities in October 2025, signaling broad abuse of exposed Oracle EBS deployments. At this scale, the wave raises the risk of repeated compromise, downstream data theft, and extortion across multiple organizations.
Related Happenings
ShinyHunters Oracle PeopleSoft data theft from 300 instances
Data Leak
H score46
First: 11.06.2026 22:39
Last: 11.06.2026 22:39
Sources 1
About this happening:
The **ShinyHunters** data-leak event against **Oracle PeopleSoft** instances exposed data from **300 instances** across **100+ organizations**, expanding the risk of theft-driven...
ShinyHunters Oracle PeopleSoft data theft from 300 instances
Data LeakAbout this happening: The **ShinyHunters** data-leak event against **Oracle PeopleSoft** instances exposed data from **300 instances** across **100+ organizations**, expanding the risk of theft-driven...
Oracle PeopleSoft PeopleTools zero-day RCE (CVE-2026-35273)
Vulnerability
H score58
First: 11.06.2026 22:39
Last: 11.06.2026 22:39
Sources 1
About this happening:
**Oracle PeopleSoft PeopleTools** **CVE-2026-35273** is a critical **zero-day RCE** affecting **versions 8.61 and 8.62**. Oracle has released **emergency mitigations** while a pat...
Oracle PeopleSoft PeopleTools zero-day RCE (CVE-2026-35273)
VulnerabilityAbout this happening: **Oracle PeopleSoft PeopleTools** **CVE-2026-35273** is a critical **zero-day RCE** affecting **versions 8.61 and 8.62**. Oracle has released **emergency mitigations** while a pat...
Oracle WebLogic Server CVE-2026-21962 rapid exploitation wave
Exploitation Wave
H score52
First: 26.03.2026 18:00
Last: 26.03.2026 18:00
Sources 1
About this happening:
**Oracle WebLogic Server** systems faced a rapid **CVE-2026-21962** exploitation wave after public exploit code appeared, creating immediate **RCE risk** for exposed servers. The...
Oracle WebLogic Server CVE-2026-21962 rapid exploitation wave
Exploitation WaveAbout this happening: **Oracle WebLogic Server** systems faced a rapid **CVE-2026-21962** exploitation wave after public exploit code appeared, creating immediate **RCE risk** for exposed servers. The...
Oracle Identity Manager and Oracle Web Services Manager unauthenticated RCE (CVE-2026-21992)
Vulnerability
H score55
First: 20.03.2026 20:48
Last: 20.03.2026 20:48
Sources 1
About this happening:
Oracle issued an **out-of-band update** to fix **CVE-2026-21992**, a **critical unauthenticated remote code execution** flaw in **Oracle Identity Manager** and **Oracle Web Servic...
Oracle Identity Manager and Oracle Web Services Manager unauthenticated RCE (CVE-2026-21992)
VulnerabilityAbout this happening: Oracle issued an **out-of-band update** to fix **CVE-2026-21992**, a **critical unauthenticated remote code execution** flaw in **Oracle Identity Manager** and **Oracle Web Servic...
Cl0p Oracle E-Business Suite zero-day extortion campaign
Campaign
H score50
First: 02.03.2026 15:53
Last: 02.03.2026 15:53
Sources 1
About this happening:
The **Cl0p ransomware and extortion group** is running an **Oracle E-Business Suite** extortion campaign that used **zero-day vulnerabilities** to access data from **more than 100...
Cl0p Oracle E-Business Suite zero-day extortion campaign
CampaignAbout this happening: The **Cl0p ransomware and extortion group** is running an **Oracle E-Business Suite** extortion campaign that used **zero-day vulnerabilities** to access data from **more than 100...
Timeline
-
12.11.2025 17:30 1 articles · 7mo ago
Oracle EBS exploitation observed
Exploitation ObservedOracle confirmed that threat actors were likely exploiting vulnerabilities against Oracle E-Business Suite environments on October 2, 2025, indicating active abuse of a previously unknown zero-day path affecting exposed Oracle instances.
Show sources
- GlobalLogic Becomes Latest Cl0p Victim After Oracle EBS Attack — www.infosecurity-magazine.com — 12.11.2025 17:30
-
12.11.2025 17:30 1 articles · 7mo ago
Oracle issues zero-day security advisory
Mitigation Patch UpdateOracle issued a security advisory on October 4, 2025 about a previously unknown zero-day exploit affecting Oracle E-Business Suite, establishing the vendor response that prompted customers to assess exposure and patch affected systems.
Show sources
- GlobalLogic Becomes Latest Cl0p Victim After Oracle EBS Attack — www.infosecurity-magazine.com — 12.11.2025 17:30
-
12.11.2025 17:30 1 articles · 7mo ago
Data exfiltration confirmed from GlobalLogic Oracle instance
Victim Impact UpdateGlobalLogic's investigation confirmed that data was exfiltrated from its Oracle environment on October 9, 2025, turning the Oracle E-Business Suite compromise into a confirmed data theft event affecting employee information.
Show sources
- GlobalLogic Becomes Latest Cl0p Victim After Oracle EBS Attack — www.infosecurity-magazine.com — 12.11.2025 17:30
-
12.11.2025 17:30 2 articles · 7mo ago
GlobalLogic discloses Oracle EBS compromise to 10,471 people
Initial DisclosureGlobalLogic notified 10,471 current and former employees that personal data from its Oracle E-Business Suite platform was compromised in a large-scale data extortion campaign, with exposed HR records including names, addresses, phone numbers, dates of birth, passport information, salary information, and bank account details.
Show sources
- GlobalLogic Becomes Latest Cl0p Victim After Oracle EBS Attack — www.infosecurity-magazine.com — 12.11.2025 17:30
- GlobalLogic Becomes Latest Cl0p Victim After Oracle EBS Attack — www.infosecurity-magazine.com — 12.11.2025 17:30