logo

CrowdStrike Identifies Campaign Targeting Oracle E-Business Suite via Zero-Day Vulnerability (now tracked as CVE-2025-61882)

ID: cfc5d8e0-ae34-5473-98f9-7b1fb5491d8d

STIX ID: report--cfc5d8e0-ae34-5473-98f9-7b1fb5491d8d

Feed Name: Crowdstrike Blog

Threat Score
90/100

Date Published: 2025-10-06

Date Updated: 2026-04-27

Author: Counter Adversary Operations

...
...

CrowdStrike reports a mass-exploitation campaign exploiting a novel Oracle E-Business Suite zero-day (CVE-2025-61882) that enables unauthenticated RCE and has been used for data exfiltration; the report details exploitation vectors (authentication bypass to /OA_HTML/SyncServlet and malicious XSLT template upload via XML Publisher), includes IOCs and a published PoC, and attributes activity with moderate confidence to GRACEFUL SPIDER while warning that PoC release will likely spur further weaponization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.