2025 Oracle E-Business Suite — zero-day (CVE-2025-61882) Clop mass-exploitation wave
Data compromised
Customer-hosted EBS environments globally—Oracle published emergency patches; victim counts vary by organization
Technical writeup
In mid-2025 researchers and Oracle documented active exploitation of a critical Oracle E-Business Suite zero-day (CVE-2025-61882) tied to widespread Clop ransomware campaigns against on-premises EBS customers—not Oracle Cloud SaaS tenants as a single monolithic leak. Oracle issued emergency mitigation guidance and patches; victim numerators belong to each customer organization. BreachHistory tracks this row under Oracle as the vendor/software root of a global exploitation wave with recordsAffected 0 at the vendor level.
Root cause
Critical Oracle EBS zero-day exploited across customer deployments; Clop extortion