logo

Clop Ransomware Hits Oracle Customers Via Zero-Day Flaw

ID: 7567ae5b-961d-50a9-940c-36a2e6bd5372

STIX ID: report--7567ae5b-961d-50a9-940c-36a2e6bd5372

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-10-06

Date Updated: 2026-05-05

Author: Alexander Culafi

...
...

A critical unauthenticated remote code execution vulnerability (CVE-2025-61882, CVSS 9.8) in Oracle E-Business Suite's Concurrent Processing/BI Publisher Integration is being actively exploited, with extortion emails claiming responsibility by the Clop ransomware group; Oracle has published an advisory and indicators of compromise and urges affected customers (EBS versions 12.2.3–12.2.14) to apply security updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.