CVE-2025-61882: Oracle E-Business Suite unauthenticated RCE, exploited as a zero-day
The short version: CVE-2025-61882 is an unauthenticated flaw in Oracle E-Business Suite (the Concurrent Processing / BI Publisher Integration component) that leads to remote code execution and server takeover. It was exploited as a zero-day in a mass data-theft and extortion campaign, Oracle issued an emergency Security Alert, and it's in CISA's KEV catalog with an EPSS near the top. Steady hands — but move: patch and assume pre-patch exposure.
At a glance
| Fact | Detail |
|---|---|
| Our severity take | High — in practice and on paper |
| CVSS v3.1 (NVD) | 9.8 — Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.7% · 99.95th percentile (2026-07-17) |
| In CISA KEV? | Yes — remediation was due 2025-10-27 |
| Known exploited? | Yes — zero-day exploitation in a mass extortion campaign (known ransomware/extortion use) |
| Vulnerability type | CWE-287 improper authentication → unauthenticated remote code execution |
| Requires authenticated session? | No — pre-authentication |
| Affected | Oracle E-Business Suite (Concurrent Processing) 12.2.3 through 12.2.14 |
| Fixed in | Per Oracle's emergency Security Alert for CVE-2025-61882 — apply the vendor patch |
What you need to know
Oracle E-Business Suite (EBS) is a large enterprise application platform (financials, supply chain, HR) that is frequently internet-facing for remote and partner access. CVE-2025-61882 is an improper-authentication flaw in the Concurrent Processing product's BI Publisher Integration that lets an unauthenticated attacker with HTTP access compromise the component and execute code — full takeover.
Why this one was top-of-queue the moment it broke:
- It's unauthenticated and low-complexity. Network access over HTTP is enough.
- It hits business-critical data. EBS holds financial and operational records; a takeover reaches the crown jewels.
- It was a live zero-day in an extortion campaign. Attackers used it to steal data at scale before patches were broadly applied, prompting Oracle's out-of-band Security Alert.
- EPSS sits near the ceiling. Exploitation is mechanical and widespread.
How serious we see it
High — the 9.8 is fully earned.
Unauthenticated code execution on an internet-facing enterprise application, used as a zero-day in a mass extortion campaign and in CISA's KEV catalog, is unambiguous. Paper and practice agree.
The bounded, reassuring part: it affects a specific EBS version range, Oracle's fix is published, and exposure is quick to confirm. The catch is the zero-day window — assume an exposed, unpatched EBS may already have been hit, and pair patching with a data-theft and compromise review.
Recommendations
Straight from Oracle's Security Alert and CISA:
- Patch now. Apply Oracle's emergency fix for CVE-2025-61882 to affected EBS 12.2.3–12.2.14.
- Reduce exposure. Restrict internet access to EBS where you can while you patch and investigate.
- Hunt — assume pre-patch exposure. Review logs for exploitation of the Concurrent Processing / BI Publisher endpoints and for signs of data exfiltration; follow Oracle's indicators.
- If you find indicators, respond fully. Rotate credentials and secrets, and engage incident response given the extortion context.
- Confirm your exposure first. Verify whether you run an affected EBS version and whether it's internet-reachable.
How BreachRisk sees it
BreachRisk works from the outside in. From little more than your domain it discovers internet-facing Oracle E-Business Suite interfaces, fingerprints the product and version, and flags exposure tied to this KEV-listed, actively exploited flaw — pushed to the top of your results because it's in KEV and was a live zero-day. Because reliable verification would require a blind, potentially disruptive exploit attempt with external interaction, BreachRisk detects and flags the exposed, affected server rather than attempting exploitation.
That outside-in view is exactly what you want when a zero-day extortion campaign is running: the exposed, affected EBS is already mapped, so you go straight to patch-and-verify.