watchTowr[verified]@watchtowrcyberExploit
This link appears to present a pre‑authorization remote code execution chain for CVE‑2025‑61882 with likely PoC code, but there is no evidence of active exploitation or patch information.
Team Cymru Research[verified]@teamcymru_S2Active Exploitation
The post lists the top 25 CVEs that experienced exploitation attempts during a 14‑day period, indicating active exploitation activity observed by Team Cymru.
Teegra 🧝♀️𝕏[verified]@TeeegraActive Exploitation
Attackers are actively exploiting CVE‑2026‑46817 on Oracle E‑Business Suite using an unauthenticated HTTP‑based RCE; a patch was released in May 2026, yet at least 200 exposed systems remain vulnerable.
RIFFSEC[verified]@getriffsecActive Exploitation
The text reports that the Cl0p ransomware group actively exploited CVE-2025-61882 (CVSS 9.8) in a wave of extortion attacks against Oracle E-Business Suite, characterizing it as a significant zero-day incident in 2025.
Divinmentis[verified]@DivinmentisActive Exploitation
Bimbo reports a breach attributed to a third‑party vendor, noting the event’s timing matches a known 2025 Oracle EBS exploitation campaign targeting CVE-2025-61882, indicating potential active exploitation without providing further technical or remediation details.
CVE Brief[verified]@DailyCVEBriefPatch
Oracle released a patch for CVE‑2025‑61882 on Oct 4 2025; the advisory lists attacker IPs and reverse‑shell patterns, indicating ongoing exploitation of a chain leading to an XSL template that calls Java.
Gagan Suie[verified]@gagansuieActive Exploitation
Cl0p leveraged an unauthenticated RCE in Oracle E‑Business Suite (CVE‑2025‑61882) to extort 29 organizations; the vulnerability was actively exploited in the wild before a patch was available.
hito[verified]@_hito_General
The text references CVE‑2025‑61882 and provides a link to a news article, but offers no information on PoC, exploit code, active exploitation, patches, technical specifics, or debunking claims.