>> All posts

CVE-2025-61882: Oracle E-Business Suite unauthenticated RCE, exploited as a zero-day

The short version: CVE-2025-61882 is an unauthenticated flaw in Oracle E-Business Suite (the Concurrent Processing / BI Publisher Integration component) that leads to remote code execution and server takeover. It was exploited as a zero-day in a mass data-theft and extortion campaign, Oracle issued an emergency Security Alert, and it's in CISA's KEV catalog with an EPSS near the top. Steady hands — but move: patch and assume pre-patch exposure.

At a glance

FactDetail
Our severity takeHigh — in practice and on paper
CVSS v3.1 (NVD)9.8 — Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.7% · 99.95th percentile (2026-07-17)
In CISA KEV?Yes — remediation was due 2025-10-27
Known exploited?Yes — zero-day exploitation in a mass extortion campaign (known ransomware/extortion use)
Vulnerability typeCWE-287 improper authentication → unauthenticated remote code execution
Requires authenticated session?No — pre-authentication
AffectedOracle E-Business Suite (Concurrent Processing) 12.2.3 through 12.2.14
Fixed inPer Oracle's emergency Security Alert for CVE-2025-61882 — apply the vendor patch

What you need to know

Oracle E-Business Suite (EBS) is a large enterprise application platform (financials, supply chain, HR) that is frequently internet-facing for remote and partner access. CVE-2025-61882 is an improper-authentication flaw in the Concurrent Processing product's BI Publisher Integration that lets an unauthenticated attacker with HTTP access compromise the component and execute code — full takeover.

Why this one was top-of-queue the moment it broke:

  • It's unauthenticated and low-complexity. Network access over HTTP is enough.
  • It hits business-critical data. EBS holds financial and operational records; a takeover reaches the crown jewels.
  • It was a live zero-day in an extortion campaign. Attackers used it to steal data at scale before patches were broadly applied, prompting Oracle's out-of-band Security Alert.
  • EPSS sits near the ceiling. Exploitation is mechanical and widespread.

How serious we see it

High — the 9.8 is fully earned.

Unauthenticated code execution on an internet-facing enterprise application, used as a zero-day in a mass extortion campaign and in CISA's KEV catalog, is unambiguous. Paper and practice agree.

The bounded, reassuring part: it affects a specific EBS version range, Oracle's fix is published, and exposure is quick to confirm. The catch is the zero-day window — assume an exposed, unpatched EBS may already have been hit, and pair patching with a data-theft and compromise review.

Recommendations

Straight from Oracle's Security Alert and CISA:

  1. Patch now. Apply Oracle's emergency fix for CVE-2025-61882 to affected EBS 12.2.3–12.2.14.
  2. Reduce exposure. Restrict internet access to EBS where you can while you patch and investigate.
  3. Hunt — assume pre-patch exposure. Review logs for exploitation of the Concurrent Processing / BI Publisher endpoints and for signs of data exfiltration; follow Oracle's indicators.
  4. If you find indicators, respond fully. Rotate credentials and secrets, and engage incident response given the extortion context.
  5. Confirm your exposure first. Verify whether you run an affected EBS version and whether it's internet-reachable.

How BreachRisk sees it

BreachRisk works from the outside in. From little more than your domain it discovers internet-facing Oracle E-Business Suite interfaces, fingerprints the product and version, and flags exposure tied to this KEV-listed, actively exploited flaw — pushed to the top of your results because it's in KEV and was a live zero-day. Because reliable verification would require a blind, potentially disruptive exploit attempt with external interaction, BreachRisk detects and flags the exposed, affected server rather than attempting exploitation.

That outside-in view is exactly what you want when a zero-day extortion campaign is running: the exposed, affected EBS is already mapped, so you go straight to patch-and-verify.

References

See your cyber risk, proven.