← All CVEs NewScan detects
criticalKEV

CVE-2025-61882

Oracle E-Business Suite pre-auth RCE in the internet-facing web tier - the Cl0p mass-extortion campaign (CVSS 9.8)

Severity
critical
Affected product
Oracle E-Business Suite
Affected versions
Oracle E-Business Suite all versions before the fix
CISA KEV
Listed as a known exploited vulnerability
EPSS
94% chance of exploitation in the next 30 days
Added to NewScan
2026-08-06
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Oracle E-Business Suite appliance and reports this CVE when the detected version falls inside the affected range below.

Exploited from ~2025-08-09, emergency patch 2025-10-04. No version gate: the EBS login surface does not publish the 12.2.x release anonymously, so this is an advisory observation and the operator confirms the patch level.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →