Wednesday, September 16, 2026

CISA Warns of Oracle E-Business Suite SSRF Vulnerability Actively Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Oracle E-Business Suite vulnerability to its Known Exploited Vulnerabilities catalog after detecting active exploitation in the wild.

The security flaw, tracked as CVE-2025-61884, poses significant risks to organizations running the widely-deployed enterprise resource planning software.

Critical SSRF Flaw Requires Immediate Action

CVE-2025-61884 is a server-side request forgery vulnerability affecting the Runtime component of Oracle Configurator within Oracle E-Business Suite.

The flaw allows remote attackers to exploit the vulnerability without requiring any authentication credentials, making it particularly dangerous for exposed systems.

CVE IDAffected ProductVulnerability Type
CVE-2025-61884Oracle E-Business Suite (Runtime component of Oracle Configurator)Server-Side Request Forgery (SSRF)

Server-side request forgery attacks enable threat actors to manipulate the server into making unauthorized requests to internal or external resources, potentially exposing sensitive data or facilitating deeper network penetration.

The vulnerability received a CWE-918 classification, which specifically identifies SSRF weaknesses where applications fail to validate user-supplied URLs properly.

Security researchers warn that attackers exploiting this flaw could bypass network access controls, interact with internal services, and potentially exfiltrate confidential information from backend systems.

The remote exploitability without authentication makes this vulnerability especially attractive to cybercriminals seeking easy entry points into corporate networks.

CISA added CVE-2025-61884 to the Known Exploited Vulnerabilities catalog on October 20, 2025, signaling confirmed active exploitation attempts.

Federal agencies operating Oracle E-Business Suite installations must apply security patches or implement vendor-recommended mitigations by November 10, 2025, according to Binding Operational Directive 22-01.

Organizations unable to remediate the vulnerability within the specified timeframe should discontinue using the affected product until proper protections can be implemented.

While CISA has not yet confirmed whether this vulnerability has been weaponized in ransomware campaigns, the unknown status emphasizes the need for caution.

Organizations should follow applicable BOD 22-01 guidance for cloud services and coordinate with Oracle to obtain the latest security updates addressing this critical flaw.

Security teams managing Oracle E-Business Suite deployments should immediately review their installations for exposure to CVE-2025-61884.

Priority actions include applying vendor-supplied patches, implementing network segmentation to limit potential SSRF exploitation, and monitoring for suspicious outbound requests from Oracle Configurator components.

Organizations should also conduct thorough security assessments to identify any indicators of compromise that may suggest prior exploitation attempts.

The addition of this vulnerability to CISA’s catalog underscores the critical importance of maintaining current patch levels for enterprise applications and implementing defense-in-depth strategies to protect against emerging threats.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Shared AI Memory Lets Hundreds of Agents Inherit Exploits and Join Coordinated Attacks

A shared message board turned isolated AI agents into...

NIST Issues New Guidance to Protect SSO and API Tokens From Theft and Forgery

The National Institute of Standards and Technology (NIST) has...

12 Best CIEM Tools Compared (2026): Features & Pricing

Quick Answer: CIEM bills per identity or per cloud...

12 Best CASB Solutions Compared (2026): Features & Pricing

Quick Answer: Nobody buys standalone CASB anymore you buy...

Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results

Iranian state-linked cyber actors are using fake AI applications,...

Apple Releases iOS 27 Security Update to Fix Over 120 Vulnerabilities

Apple has released iOS 27 and iPadOS 27, delivering...

KREMLIN Banking Malware Bypasses Chrome Security to Steal Banking Sessions

A Brazilian banking malware operation, dubbed KREMLIN, that can...

Related Articles

Recent News