tactical Vulnerabilities & CVEshigh
Cybersecurity and Infrastructure Security AgencyBio confirms exploitation of Oracle E-Business Suite CVE-2025-61884
Summary
Bottom line: the flaw was added to the Known Exploited Vulnerabilities catalog after confirmed in-the-wild abuse following the earlier zero-day campaign. Treat catalog additions as a patch deadline, not a notification.
Key claims· extracted from reporting
- Bottom line: the flaw was added to the Known Exploited Vulnerabilities catalog after confirmed in-the-wild abuse following the earlier zero-day campaign.Low · 20%action verbnamed entity×2Source: BleepingComputer
- Treat catalog additions as a patch deadline, not a notification.Low · 10%named entitySource: BleepingComputer
Heuristic extraction, verify against the original report before citing.
Tags· click to alert
Story timeline
4 updates · 91 days
- Jul 22, 2025·criticalMicrosoft Threat Intelligence
- Oct 9, 2025·criticalGoogle Threat Intelligence Group / Mandiant
- Oct 21, 2025·highSecurityWeek
- Oct 21, 2025·highcurrentBleepingComputerCybersecurity and Infrastructure Security AgencyBio confirms exploitation of Oracle E-Business Suite CVE-2025-61884