Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks
An urgent patch has been issued by Oracle to fix a serious security vulnerability in its E-Business Suite, which it claims was used in the most recent round of Cl0p data theft attacks.
The vulnerability, known as CVE-2025-61882, has an undefined issue that could make it possible for an unauthenticated attacker with HTTP network access to infiltrate and take over the Oracle Concurrent Processing component.
Oracle stated in a warning that this vulnerability can be remotely exploited without authentication, meaning that a username and password are not required to exploit it across a network. Remote code execution could occur if this vulnerability is effectively exploited.
Oracle has provided remedies for CVE-2025-61882, according to a separate advisory from Rob Duhart, the company's...

