Oracle E-Business Suite zero-day under attack

Published July 16, 2026

Oracle's E-Business Suite, a financial management tool used by businesses, has a critical flaw attackers are actively exploiting. This lets them take control of affected systems without warning.

Severity
Not scoredNo CVSS score recorded
Fix
Not confirmed
Affects
Oracle E-Business Suite
Exploited
Not confirmedNo confirmation recorded

How it works

Attackers send specially crafted requests to the Oracle E-Business Suite's financial reporting module, tricking it into running unauthorized code on the server.

What to do

Check whether the installed Oracle E-Business Suite version is older than the fixed version in the vendor advisory or current release.

Update version 12.2.13.3 or immediately to the current version using Oracle's official update tools. No workaround exists.

Technical details

Affected software: Oracle E-Business Suite

CVE-2025-61882 affects the BI Publisher Integration component of Oracle Concurrent Processing within E-Business Suite, outdated versions. It carries a outdated CVSS versions score of the latest version (critical): an unauthenticated attacker with only network access over HTTP can fully compromise the component, with high impact to confidentiality, integrity, and availability. CISA added it to its Known Exploited Vulnerabilities catalog after confirming active exploitation, and the Clop group has used it in a data-theft extortion campaign, reusing infrastructure previously tied to its 2023 MOVEit (CVE-2023-34362) attacks.