CISA Bugs: Oracle, Microsoft Vulnerabilities Exploit Targets

by Anika Shah - Technology
0 comments

# CISA Adds Five New Vulnerabilities to its Exploited list, Including oracle EBS Flaw

Oct 20, 2025Ravie LakshmananThreat Intelligence / Data Security

CISA Bugs: Oracle, Microsoft Vulnerabilities Exploit Targets

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added five security flaws to its Known Exploited Vulnerabilities (KEV) Catalog, officially confirming a recently disclosed vulnerability impacting Oracle E-business Suite (EBS) has been weaponized in real-world attacks.The security defect in question is CVE-2025-61884 (CVSS score: 7.5), which has been described as a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator that could allow attackers unauthorized access to critical data.

“This vulnerability is remotely exploitable without authentication,” CISA said.

DFIR Retainer Services

CVE-2025-61884 is the second flaw in Oracle EBS to be actively exploited along with CVE-2025-61882 (CVSS score: 9.8), a critical bug that could permit unauthenticated attackers to execute arbitrary code on susceptible instances.Earlier this month, Google Threat Intelligence Group (GTIG) a

Related Posts

Leave a Comment