Vulnerability intelligence
CVE-2025-61882
Oracle E-Business Suite Unspecified Vulnerability
Oracle E-Business Suite
Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing.
CVSS Score
—
Unrated
EPSS — Exploit Probability
100%
Riskier than 100% of all CVEs · checked 2026-09-04
Exploitation
Confirmed in the wild
Used in ransomware campaigns
Remediation
Unconfirmed
Federal deadline 2025-10-27
CISA required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2025-10-27.
4 articles across 4 outlets · first covered Jan 26, 2026 · latest Mar 23, 2026
Coverage timeline
-
M-Trends 2026: Initial Access Handoff Shrinks From Hours to 22 Secondswww.securityweek.com · Mar 23, 2026
-
MSG data breach tied to Cl0p's Oracle flaw CVE-2025-61882securityaffairs.com · Mar 3, 2026
-
CISA Makes Unpublicized Ransomware Updates to KEV Catalogwww.darkreading.com · Feb 4, 2026
-
PoC Released for Critical Oracle E-Business Suite Flaw Exploited by Ransomwaresecurityonline.info · Jan 26, 2026