CVE-2025-61882
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Oct 6, 2025
- US federal agencies must remediate it by Oct 27, 2025 (BOD 22-01)
- Attacked 1 day before the vulnerability was made public
- Confirmed by sensors, not only by reports
- Used in ransomware campaigns
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Source: CISA KEV · Sep 17, 2026 Sep 14, 2026 Sep 13, 2026 Sep 10, 2026 Sep 6, 2026 Sep 3, 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| oracle | concurrent processing | <= 12.2.14 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
