ZeroHour
The Recordpublished ()ingested

FBI, UK gov’t urge orgs to patch Oracle E-Business vuln after alleged Clop campaign

highRansomware exploited in the wildimportance 60CVE-2025-61882

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-61882
Unauthenticated Takeover of Oracle E-Business Suite Concurrent Processing

CVE-2025-61882 is a critical (CVSS 9.8) authentication flaw (CWE-287) in the BI Publisher Integration component of the Oracle Concurrent Processing product within Oracle E-Business Suite. An unauthenticated attacker with network access over HTTP can exploit it remotely with no credentials and no user interaction, achieving a takeover of Oracle Concurrent Processing with high confidentiality, integrity, and availability impact. Any organization running Oracle E-Business Suite 12.2.3 through 12.2.14 is affected, especially instances reachable from the internet. The flaw is being actively exploited in the wild: the Cl0p data-theft group has used it to breach dozens of organizations (including Harvard University, with 1.3 TB of data leaked), CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-06 with known ransomware use, and EPSS puts its 30-day exploitation probability at 99.7%.

Do: Apply Oracle's released patch or mitigations for CVE-2025-61882 to affected E-Business Suite 12.2.3-12.2.14 deployments as instructed by the vendor; per CISA KEV requirements, federal agencies must follow BOD 22-01 guidance or discontinue use if mitigations are unavailable. Until patched, limit internet exposure of EBS and its BI Publisher/Concurrent Processing HTTP endpoints, and review web and application logs for unauthenticated access and signs of Cl0p-style data theft or follow-on ransomware.

9.8100% KEV ransomware
  • Oracle E-Business Suite (Oracle Concurrent Processing, BI Publisher Integration component) 12.2.3 - 12.2.14
largetens of thousands of EBS environments worldwide across an estimated ~5,000+ customer organizations (est.)
Full article531 words · extracted from therecord.media · click to collapse

Oracle issued a security alert this weekend urging customers to patch a vulnerability currently being exploited by cybercriminals. 

Oracle’s security alert said CVE-2025-61882 impacts the Oracle E-Business Suite — a widely-used business platform containing several applications that manage finance, human resources and supply chain functions.

Oracle explained that the vulnerability, which carries a severity score of 9.8 out of 10, could be exploited remotely “without the need for a username and password.” 

Customers need to install patches from an October 2023 update before installing the new patch issued on Saturday. Oracle also shared indicators of compromise that organizations can use to support their efforts to detect and contain potential breaches. 

FBI Assistant Director Brett Leatherman said “this is ‘stop-what-you’re-doing and patch immediately’ vulnerability.” 

“The bad guys are likely already exploiting in the wild, and the race is on before others identify and target vulnerable systems,” he said in a Sunday evening post on LinkedIn. 

“In plain terms: if your [E-Business Suite] environment is reachable on the network, and especially if it’s internet facing, it’s at risk for full compromise.”

Leatherman added that Oracle E-Business Suite customers should isolate potentially affected servers and monitor threat intelligence channels because “exploit activity could escalate quickly.”

“Oracle EBS remains a backbone ERP system for major enterprises and public-sector environments, which means attackers have every incentive to weaponize this one fast,” he explained. “If you suspect compromise - please connect with us.”

Cybersecurity agencies in the U.K. and Singapore published their own advisories with similar guidance. The U.S. Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities catalog and ordered all federal civilian agencies to patch it by October 28. 

Mandiant chief technology officer Charles Carmakal tied CVE-2025-61882 to a campaign unveiled last week by the cybercriminal group Clop

The group is currently attempting to extort corporate executives by threatening to leak sensitive information they claim was stolen through the Oracle E-Business Suite. Oracle confirmed the campaign but initially said the hackers were exploiting bugs that had been addressed in a July update, without specifying which vulnerabilities were being used. 

On Sunday, Carmakal said Clop “exploited multiple vulnerabilities in Oracle [E-Business Suite] which enabled them to steal large amounts of data from several victims in August 2025.”

“Clop has been sending extortion emails to several victims since last Monday. However, please note they may not have attempted to reach out to all victims yet,” he said. 

“Multiple vulnerabilities were exploited including vulnerabilities that were patched in Oracle's July 2025 update as well as one that was patched this weekend (CVE-2025-61882).”

He added that organizations should “examine whether they were already compromised.”

Several other cybersecurity experts confirmed that Clop has been exploiting multiple vulnerabilities in Oracle E-Business Suite since August.

Jake Knott, principal security researcher at cybersecurity firm watchTowr, said exploit code for CVE-2025-61882 became public by Monday.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/fbi-uk-urge-orgs-to-patch-after-clop-campaign