CVE-2025-61882Active Exploitation(oracle / concurrent_processing)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch oracle concurrent_processing systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-10-27. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-287

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • concurrent_processing

Threat summary

  • Active exploitation appears in 20 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 29 mentions across 23 observed days

What's happening

  • Active exploitation reported across 20 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 12 signals
  • General: 7 classified signals
  • Peaked 10d ago at 3 mentions (2026-07-21); latest day: 1
  • 29 total mentions across 23 days

Affected systems

Vendors
Products
concurrent_processing

Deep dive

Activity timeline29 mentions / 23d
01223Mentions · 2026-01-27: 1Mentions · 2026-02-14: 1Mentions · 2026-02-26: 1Mentions · 2026-03-06: 1Mentions · 2026-03-10: 1Mentions · 2026-03-28: 1Mentions · 2026-04-08: 1Mentions · 2026-06-09: 1Mentions · 2026-06-29: 1Mentions · 2026-07-01: 1Mentions · 2026-07-10: 1Mentions · 2026-07-20: 2Mentions · 2026-07-21: 3Mentions · 2026-07-23: 1Mentions · 2026-07-24: 1Mentions · 2026-07-28: 1Mentions · 2026-07-30: 2Mentions · 2026-09-07: 2Mentions · 2026-09-10: 1Mentions · 2026-09-20: 1Mentions · 2026-09-21: 2Mentions · 2026-09-22: 1Mentions · 2026-10-01: 1PoC Mentioned / Linked · 2026-01-27: 1PoC Mentioned / Linked · 2026-07-20: 1Exploit Tool / Code · 2026-01-27: 1Active Exploitation · 2026-02-14: 1Active Exploitation · 2026-03-06: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-28: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-06-29: 1Active Exploitation · 2026-07-01: 1Active Exploitation · 2026-07-10: 1Active Exploitation · 2026-07-20: 2Active Exploitation · 2026-07-21: 2Active Exploitation · 2026-07-23: 1Active Exploitation · 2026-07-24: 1Active Exploitation · 2026-07-30: 1Active Exploitation · 2026-09-07: 2Active Exploitation · 2026-09-10: 1Active Exploitation · 2026-09-21: 2Patch / Workaround · 2026-06-29: 1Patch / Workaround · 2026-07-10: 1Patch / Workaround · 2026-07-23: 1Patch / Workaround · 2026-07-24: 1Patch / Workaround · 2026-07-30: 1Patch / Workaround · 2026-09-07: 1Technical Details · 2026-01-27: 1Technical Details · 2026-02-26: 1Technical Details · 2026-03-28: 1Technical Details · 2026-06-29: 1Technical Details · 2026-07-10: 1Technical Details · 2026-07-20: 1Technical Details · 2026-07-23: 1Technical Details · 2026-07-28: 1Technical Details · 2026-07-30: 1Technical Details · 2026-09-07: 1Technical Details · 2026-09-10: 1Technical Details · 2026-09-21: 101-2702-2603-1004-0806-2907-1007-2107-2407-3009-1009-2110-01
Signal classification5 categories
Active Exploitation
1864.3%
General
725.0%
Exploit
13.6%
Disclosure
13.6%
Patch
13.6%
Referenced assets17 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-271
Exploit1
2026-02-141
Active Exploitation1
2026-02-261
General1
2026-03-061
Active Exploitation1
2026-03-101
Active Exploitation1
2026-03-281
Active Exploitation1
2026-04-081
Active Exploitation1
2026-06-091
General1
2026-06-291
Active Exploitation1
2026-07-011
Active Exploitation1
2026-07-101
Active Exploitation1
2026-07-202
Active Exploitation2
2026-07-213
Active Exploitation1Disclosure1General1
2026-07-231
Active Exploitation1
2026-07-241
Active Exploitation1
2026-07-281
General1
2026-07-302
General1Patch1
2026-09-072
Active Exploitation2
2026-09-101
Active Exploitation1
2026-09-201
General1
2026-09-212
Active Exploitation2
2026-09-221
General1
Full discourse20 posts
  • watchTowr@watchtowrcyber
    Exploit

    https://labs.watchtowr.com/well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882/

    Post summary

    This link appears to present a pre‑authorization remote code execution chain for CVE‑2025‑61882 with likely PoC code, but there is no evidence of active exploitation or patch information.

    013092317.8K
    11.0K followersView on X
  • Crowdfense@crowdfense
    General

    The following weaponized vulnerabilities have been added to our n-day feed: - CVE-2025-61882: Oracle EBS - RCE - CVE-2026-24423: SmarterMail - RCE - CVE-2026-20941: Host Process - LPE - 0DAY-2026-0001: Visual Studio - Info Disclosure https://www.crowdfense.com/n-day-feed/

    Post summary

    The feed lists several weaponized vulnerabilities with basic type information but provides no details on PoC, exploitation, or patches.

    06029102.0K
    2.9K followersView on X
  • Team Cymru Research@teamcymru_S2
    Active Exploitation

    🚨 Top 25 CVE Exploitation Attempts - Team Cymru - S2 (Ranked by unique source IPs over 14 days) 1. CVE-2025-0282 · Ivanti Connect Secure 2. CVE-2025-49706 · SharePoint 3. CVE-2020-3452 · Cisco ASA 4. CVE-2025-61884 · Oracle EBS 5. CVE-2024-32113 · Apache OFBiz 6. CVE-2025-53770 · SharePoint 7. CVE-2025-24893 · XWiki 8. CVE-2025-61882 · Oracle EBS 9. CVE-2025-5777 · Citrix NetScaler 10. CVE-2025-34028 · Commvault 11. CVE-2024-57727 · SimpleHelp 12. CVE-2025-20362 · Cisco ASA/FTD 13. CVE-2024-1212 · Kemp LoadMaster 14. CVE-2024-38856 · Apache OFBiz 15. CVE-2022-40684 · Fortinet 16. CVE-2024-9465 · Palo Alto Expedition 17. CVE-2025-11371 · Gladinet CentreStack 18. CVE-2025-58360 · GeoServer 19. CVE-2025-57819 · FreePBX 20. CVE-2025-31324 · SAP NetWeaver 21. CVE-2024-7593 · Ivanti vTM 22. CVE-2025-31125 · Vite Dev Server 23. CVE-2025-64446 · FortiWeb 24. CVE-2024-12987 · DrayTek Vigor 25. CVE-2018-7600 · Drupal

    Post summary

    The post lists the top 25 CVEs that experienced exploitation attempts during a 14‑day period, indicating active exploitation activity observed by Team Cymru.

    070921.2K
    5.5K followersView on X
  • Teegra 🧝‍♀️𝕏@Teeegra
    Active Exploitation

    مهاجمان سایبری بهره‌برداری فعال از یک آسیب‌پذیری بحرانی با شناسه CVE-2026-46817 را در نرم‌افزار مالی Oracle E-Business Suite (EBS) آغاز کرده‌اند. این نقص امنیتی که در مؤلفه انتقال فایل محصول Oracle Payments کشف شده به مهاجمان احراز هویت‌نشده امکان می‌دهد از طریق دسترسی شبکه‌ای HTTP و با حملاتی کم‌پیچیدگی، کنترل سیستم‌های آسیب‌پذیر را در دست بگیرند. شرکت اطلاعات تهدید Defused اعلام کرد که نخستین تلاش‌های بهره‌برداری از این آسیب‌پذیری در آخر هفته گذشته بر روی سیستم‌های فریب (honeypot) این شرکت مشاهده شده است. این آسیب‌پذیری با امتیاز CVSS 9.8 رتبه‌بندی شده و اوراکل در به‌روزرسانی امنیتی ماه مه ۲۰۲۶ وصله آن را منتشر کرده بود. سازمان Shadowserver اکنون بیش از ۴۵۰ نمونه Oracle EBS در معرض اینترنت را رصد می‌کند که نزدیک به ۲۰۰ مورد از آن‌ها در آمریکا و اروپا قرار دارند. این رویداد در حالی رخ می‌دهد که باند اخاذی Clop پیش‌تر از یک آسیب‌پذیری دیگر Oracle EBS با شناسه CVE-2025-61882 در حملات روز-صفر (zero-day) علیه چندین دانشگاه آمریکایی از جمله هاروارد، دانشگاه پنسیلوانیا و دارتموث و همچنین واشنگتن‌پست و لاجیتک بهره‌برداری کرده بود. آژانس امنیت سایبری و زیرساخت آمریکا (CISA) نیز در هفته‌های اخیر چندین آسیب‌پذیری بحرانی در محصولات اوراکل از جمله Oracle WebLogic Server و PeopleSoft Suite را به‌عنوان مورد بهره‌برداری فعال علامت‌گذاری کرده است. در مجموع، CISA طی سال‌های اخیر ۴۴ آسیب‌پذیری در محصولات مختلف اوراکل را به‌عنوان مورد سوءاستفاده در دنیای واقعی شناسایی کرده که ۱۳ مورد از آن‌ها در حملات باج‌افزاری (ransomware) نیز به‌کار رفته‌اند.

    Post summary

    Attackers are actively exploiting CVE‑2026‑46817 on Oracle E‑Business Suite using an unauthenticated HTTP‑based RCE; a patch was released in May 2026, yet at least 200 exposed systems remain vulnerable.

    010151901
    19.3K followersView on X
  • KEVIntel@kev_intel
    Active Exploitation

    Top exploited KEVs we tracked over the past 7 days: 1 CVE-2025-61882 - Oracle EBS 2 CVE-2026-10520 - Ivanti Sentry 3 CVE-2022-47945 - ThinkPHP 4 CVE-2026-20230 - Cisco UCM 5 CVE-2026-46817 - Oracle EBS 6 CVE-2026-20253 - Splunk

    Post summary

    The tweet highlights CVEs identified as top exploited KEVs tracked over the past 7 days, suggesting ongoing exploitation, but provides no technical, PoC, or patch details.

    02020328
    61 followersView on X
  • LeMagIT@LeMagIT
    General

    Guerre entre cybercriminels ! 💥 Les ShinyHunters ont attaqué Cl0p en réaction à une vulnérabilité (CVE-2025-61882). Un cas d'école sur la dynamique des menaces. 🛡️ Lisez notre analyse. 👇 https://www.lemagit.fr/actualites/366650835/Les-ShinyHunters-sattaquent-a-Cl0p https://t.co/td5sFPQWcS

    Post summary

    The tweet references CVE-2025-61882 in the context of a cybercriminal conflict but lacks specific indicators of PoC, exploitation, or remediation.

    10000448
    17.9K followersView on X
  • RIFFSEC@getriffsec
    Active Exploitation

    Cl0p was no random victim. The group was behind, among other operations, this year’s wave of extortion targeting Oracle E-Business Suite (CVE-2025-61882, CVSS 9.8) — one of the more significant zero-day incidents affecting enterprise software in 2025.

    Post summary

    The text reports that the Cl0p ransomware group actively exploited CVE-2025-61882 (CVSS 9.8) in a wave of extortion attacks against Oracle E-Business Suite, characterizing it as a significant zero-day incident in 2025.

    10000185
    3.0K followersView on X
  • Divinmentis@Divinmentis
    Active Exploitation

    The company traced the theft to a third-party vendor and said it confirmed the sensitive file on Aug. 19. The timeline aligns with the 2025 Oracle EBS campaign exploiting CVE-2025-61882, but Bimbo did not name the flaw or attribute the breach. https://t.co/rcIvSYuAaF

    Post summary

    Bimbo reports a breach attributed to a third‑party vendor, noting the event’s timing matches a known 2025 Oracle EBS exploitation campaign targeting CVE-2025-61882, indicating potential active exploitation without providing further technical or remediation details.

    1000071
    60 followersView on X
  • CVE Brief@DailyCVEBrief
    Patch

    LOOK BACK — Oracle broke its quarterly patch cadence on Oct 4, 2025 to ship CVE-2025-61882, with attacker IPs and reverse-shell patterns in the advisory. Cl0p had been in EBS customers since Aug 9. The 9.8 was a five-link chain ending at an XSL template that calls Java. https://t.co/3pWd1nI6Fx

    Post summary

    Oracle released a patch for CVE‑2025‑61882 on Oct 4 2025; the advisory lists attacker IPs and reverse‑shell patterns, indicating ongoing exploitation of a chain leading to an XSL template that calls Java.

    1000087
    23 followersView on X
  • iototsecnews@iototsecnews
    General

    Black Kite 2026年ランサムウェア動向を分析:被害組織は7,551件で過去最多を記録 https://iototsecnews.jp/2026/07/21/2026-ransomware-report-reveals-7551-victims-146-active-groups-and-qilins-443-surge/ ランサムウェア被害が急増している主な原因は、外部から確認できるシステムの弱点を、攻撃者が効率よく狙っている点にあります。具体的には、Oracle E-Business Suite の脆弱性 CVE-2025-61882 などへのパッチ未適用や、DMARC の設定ミス、流出した認証情報の露出などが挙げられます。また、SaaS プラットフォームにおける OAuth トークンの悪用や、AI の普及による攻撃作業の効率化も被害を広げる要因となっています。攻撃者は防御側と比較して、多くの外部露出情報を把握しているため、自組織の公開情報や認証情報の管理状況を継続的に確認し、弱点を適切に塞ぐことが大切になります。 #BlackKite #Qilin #Ransomware

    Post summary

    The report highlights a surge in ransomware victims, attributing attacks to unpatched Oracle vulnerabilities, misconfigured DMARC, and leaked credentials, underscoring the need for better exposure monitoring.

    01000181
    503 followersView on X
  • Gagan Suie@gagansuie
    Active Exploitation

    29 organizations extorted. Nobody noticed the theft for seven weeks. Cl0p exploited an unauthenticated RCE in Oracle E-Business Suite (CVE-2025-61882) from August 9, 2025. Weeks before a patch existed.

    Post summary

    Cl0p leveraged an unauthenticated RCE in Oracle E‑Business Suite (CVE‑2025‑61882) to extort 29 organizations; the vulnerability was actively exploited in the wild before a patch was available.

    10000141
    193 followersView on X
  • hito@_hito_
    General

    CVE-2025-61882 のあれか…… https://news.mynavi.jp/techplus/article/20260609-4509833/

    Post summary

    The text references CVE‑2025‑61882 and provides a link to a news article, but offers no information on PoC, exploit code, active exploitation, patches, technical specifics, or debunking claims.

    00010232
    2.2K followersView on X
  • Grok@grok
    Active Exploitation

    Cl0p's evolved post-MOVEit by hitting successors like Cleo MFT (CVEs 2024) and Oracle EBS (CVE-2025-61882, exploited Aug 2025). New tactics: zero-day mass exfil (no encryption), web shells for stealthy data theft, and quadruple extortion—leaks, customer/partner notifications, direct exec emails, and harassment. Victims respond faster via rapid EDR anomaly spotting, pre-patched alternatives, tested backups, and zero known payouts in these 2025 waves (per Coveware/BankInfoSecurity). They assess data value quicker and skip negotiations amid scam risks. Defenses are catching up.

    Post summary

    The text reports that Cl0p exploited CVE-2025-61882 in August 2025, indicating active use, but provides no technical exploit details or patch information.

    01000191
    8.4M followersView on X
  • CyberPrism@CyberPrismApp
    Active Exploitation

    📈 Qilin grew 10x in 9 months to become the dominant group. 🎭 Clop returned from a 6-month dormancy with mass exploitation of Oracle E-Business Suite (CVE-2025-61882). 🔄 40% of ransomware incidents have infostealer involvement — stolen credentials are the dominant initial access vector. The ransomware → infostealer → breach pipeline is circular and self-reinforcing.

    Post summary

    CVE-2025‑61882 in Oracle E‑Business Suite is reportedly being actively exploited by the Clop ransomware group.

    10000159
    12 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2025-61882 Product: Oracle / E-Business Suite Summary: VulnCheck reports real-world exploitation activity affecting Oracle / E-Business Suite. Evidence: Public PoC/exploit available; Ransomware use confirmed; Active exploitation reported; Severe impact class Impact: The vulnerability is associated with ransomware activity and may contribute to compromise of exposed systems. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 04 Oct 2025 Source: https://vulncheck.com/xdb/8db320d42361 #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #Oracle #E_BusinessSuite #CVE_2025_61882 #ActiveExploitation #Exploit #Ransomware #RansomwareAttack

    0000087
    226 followersView on X
  • General Intels Daily@intels_daily
    Active Exploitation

    🟠 𝗛𝗜𝗚𝗛 · 𝗗𝗶𝘀𝗰𝘂𝘀𝘀𝗶𝗼𝗻 🏢 Target: 𝗖𝗹𝗼𝗽 🧩 Products: 𝗚𝗿𝗮𝘃 𝗖𝗠𝗦, 𝗢𝗿𝗮𝗰𝗹𝗲 𝗘-𝗕𝘂𝘀𝗶𝗻𝗲𝘀𝘀 𝗦𝘂𝗶𝘁𝗲 🛡️ CVE-2025-61882 The threat actor ShinyHunters compromised the Clop ransomware group's leak site by exploiting a vulnerability in Grav CMS. ShinyHunters claims to have stolen source code, system logs, and the private onion keys for the Clop site, and intends to extort the Clop group. The attack is described as retaliation for threats made by Clop against ShinyHunters members following a dispute over an Oracle E-Business Suite exploit. #ThreatIntel #CTI

    Post summary

    ShinyHunters allegedly exploited CVE-2025-61882 in Grav CMS to breach the Clop ransomware group's leak site, stealing source code, logs, and onion keys as retaliation.

    00000439
    692 followersView on X
  • free tokens@jere_knh2
    General

    Por qué se odian: viene de la campaña de Oracle E-Business Suite de Cl0p en 2025 (CVE-2025-61882). Según ShinyHunters, un representante de Cl0p le escribió esto, del ruso: "I have more money than you and all of your people combined, I'll kill you soon." Ahora tienen sus claves.

    Post summary

    The post references a 2025 Cl0p campaign against Oracle E‑Business Suite (CVE‑2025‑61882) and includes a threatening message from a threat actor, but provides no technical details, PoC, exploit, or remediation information.

    00000107
    8 followersView on X
  • JNR Management@jnrmanagement
    Active Exploitation

    🚨 Bimbo Bakeries USA Confirms Employee SSN Breach via Oracle EBS CVE-2025-61882 Zero-Day- Clop Ransomware Group Linked, Breach Occurred December 2025, Disclosed September 2026. 👉 Read More: https://www.jnrmanagement.com/bimbo-bakeries-usa-confirms-data-breach-oracle-ebs-cve-2025-61882-clop-zero-day.html #CyberSecurity #JNRManagement #CISO #BimboBakeries #OracleEBS https://t.co/UVqiV1saio

    Post summary

    Bimbo Bakeries USA confirmed an employee SSN breach caused by a zero‑day exploit in Oracle EBS (CVE‑2025‑61882) linked to the Clop ransomware group, indicating the vulnerability was actively exploited in December 2025.

    00000163
    182 followersView on X
  • The Daily Tech Feed@dailytechonx
    Active Exploitation

    Bimbo Bakeries USA just confirmed a breach after attackers exploited a zero-day in Oracle EBS. Employee names & SSNs exposed. Critical bug CVE-2025-61882 in BI Publisher was involved. If you’re running EBS versions 12.2.3-12.2.14, make sure the October 2025 patch is applied. Free credit monitoring being offered. #OracleEBS #DataBreach #CVE2025-61882 #Clop #Cybersecurity #EmployeeData https://thedailytechfeed.com/bimbo-bakeries-usa-hit-by-zero-day-in-oracle-e-business-suite/

    Post summary

    Bimbo Bakeries USA suffered a breach after attackers exploited zero‑day CVE‑2025‑61882 in Oracle EBS, exposing employee data; an October 2025 patch is recommended and free credit monitoring is offered.

    0000089
    713 followersView on X
  • CVE Brief@DailyCVEBrief
    General

    Full Look Back: the 2003 reporting engine at the root of it, the chain watchTowr pulled apart, and what the record now shows about the timeline: https://cvebrief.com/cve/CVE-2025-61882/ https://t.co/Ml1olJEW1R

    Post summary

    The tweet merely directs readers to a CVE record without offering any additional details, proof of concept, exploit code, patch, or discussion of active exploitation.

    0000039
    23 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporacleconcurrent_processing---

Explore more