• News/
  • https://www.theregister.com/2025/10/06/clop_oracle_ebs_zeroday/

Clop crew hits Oracle E-Business Suite users with fresh zero-day

The Register
·
Carly Page
·
Published Oct 6, 2025
·
Updated

Oracle rushed out an emergency fix over the weekend for a zero-day vulnerability in its E-Business Suite (EBS) that criminal crew Clop has already abused for data theft and extortion. The flaw, tracked as CVE-2025-61882, allows unauthenticated remote code execution and carries a CVSS severity score of 9.8 – the kind of score that tells security teams this one can't wait. The bug marks the latest twist in a saga that began when Oracle warned last week that Clop had been exploiting older, unpatched EBS flaws in a wave of extortion attacks. At the time, the company said the activity was tied to vulnerabilities addressed in its July Critical Patch Update. However, the crooks had a fresh ace up their sleeve: a previously unknown zero-day that Oracle now admits was being used in the same campaign. Mandiant confirmed to The Register that Clop has exploited multiple vulnerabilities in Oracle's EBS, including this new zero-day. In a post on LinkedIn, Mandiant CTO Charles Carmakal elaborated, warning of "mass exploitation" by Clop. "Clop exploited multiple vulnerabilities in Oracle EBS which enabled them to steal large amounts of data from several victims in August 2025," he wrote. "CVE-2025-61882 is a critical (9.8 CVSS) vulnerability that enables unauthenticated remote code execution. Given the broad mass 0-day exploitation that has already occurred... organizations should examine whether they were already compromised." Oracle is also sounding the alarm bells, warning in its advisory...

Read full article

Affected Software

1 affected component
Oracle E-Business Suite

Frequently Asked Questions

1

Which systems are affected by CVE-2025-61882?

The vulnerability affects Oracle E-Business Suite. It allows unauthenticated remote code execution and has a CVSS severity score of 9.8.

2

Has the vulnerability been exploited in the wild?

Yes. Oracle acknowledged that the previously unknown zero-day was used in the same Clop extortion campaign involving older unpatched EBS flaws, and Mandiant confirmed Clop exploited it.

3

What impact has been reported from the Clop activity?

Mandiant said Clop exploited multiple Oracle EBS vulnerabilities to steal large amounts of data from several victims in August 2025. The campaign involved data theft and extortion.

4

What action does the article indicate EBS users should take?

Oracle issued an emergency fix for CVE-2025-61882 over the weekend. Given the unauthenticated remote-code-execution impact, active exploitation, and 9.8 score, EBS users should treat the fix as urgent.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203