Oracle released an emergency update for a critical Oracle E‑Business Suite vulnerability, CVE-2025-61882, after reports that the Cl0p group actively exploited it in data theft and extortion attacks [securityweek.com#1][thehackernews.com#1][theregister.com#1]. The flaw allows unauthenticated remote code execution via HTTP and carries a CVSS score of 9.8, meaning attackers could potentially take control of affected systems if unpatched [thehackernews.com#1][bleepingcomputer.com#1][betanews.com#1].
Highlights:
- Critical severity: The bug is rated CVSS 9.8 and enables unauthenticated remote code execution via HTTP, potentially allowing full system compromise [thehackernews.com#1][bleepingcomputer.com#1][betanews.com#1].
- Active exploitation: Oracle and security outlets report the Cl0p group has exploited the flaw for data theft and extortion campaigns [securityweek.com#1][bleepingcomputer.com#1][theregister.com#1].
- Emergency fix: Oracle issued an emergency Security Alert and released patches addressing CVE-2025-61882 [thehackernews.com#1][betanews.com#1][securityweek.com#1].
- Affected product: The vulnerability targets Oracle E‑Business Suite and is reachable over the network via HTTP [thehackernews.com#1][bleepingcomputer.com#1].
- Risk context: Reports tie exploitation to data theft and extortion activity, increasing urgency for rapid patching [theregister.com#1][securityweek.com#1].
Perspectives:
- Oracle: Oracle released an emergency Security Alert for CVE-2025-61882 in E‑Business Suite and warned the issue is remotely exploitable without authentication. (BetaNews)
- Security analysts: Coverage attributes the wave of data theft and related extortion to the Cl0p group exploiting this E‑Business Suite zero‑day. (The Register)
- Threat reporting: Analysts note the flaw could let an unauthenticated attacker compromise and take control of Oracle E‑Business Suite over HTTP. (The Hacker News)
Sources:
- Oracle E-Business Suite Zero-Day Exploited in Cl0p Attacks – securityweek.com
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks – thehackernews.com
- Oracle patches EBS zero-day exploited in Clop data theft attacks – bleepingcomputer.com
- Oracle releases emergency patch to address Cl0p data theft attacks in E-Business Suite – betanews.com
- Clop crew hits Oracle E-Business Suite users with fresh zero-day – theregister.com