← Oracle

2025 Oracle E-Business Suite — zero-day (CVE-2025-61882) Clop mass-exploitation wave

2025 Unknown records affected Share on X

Data compromised

Customer-hosted EBS environments globally—Oracle published emergency patches; victim counts vary by organization

Technical writeup

In mid-2025 researchers and Oracle documented active exploitation of a critical Oracle E-Business Suite zero-day (CVE-2025-61882) tied to widespread Clop ransomware campaigns against on-premises EBS customers—not Oracle Cloud SaaS tenants as a single monolithic leak. Oracle issued emergency mitigation guidance and patches; victim numerators belong to each customer organization. BreachHistory tracks this row under Oracle as the vendor/software root of a global exploitation wave with recordsAffected 0 at the vendor level.

Root cause

Critical Oracle EBS zero-day exploited across customer deployments; Clop extortion

References