Product of Oracle

E-Business Suite

As of , 4 Oracle E-Business Suite vulnerabilities are on CISA's list of exploited vulnerabilities, 3 of them used in ransomware campaigns; 1 was added in 2026. Patch first: CVE-2025-61884.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2025-61884Server-Side Request Forgery (SSRF)Oracle E-Business SuitePatch nowRansomware use, listed within a year0.96
2CVE-2026-46817Improper Privilege ManagementOracle E-Business SuitePatch nowForensic triage required by CISA0.01
3CVE-2025-61882UnspecifiedOracle E-Business SuitePatch this weekRansomware use; Metasploit module; EPSS 0.990.99
4CVE-2022-21587UnspecifiedOracle E-Business SuitePatch this weekRansomware use; Metasploit module; EPSS 0.980.98

Added each year

0.511.522023: 1120232024: nonenone20242025: 2220252026: 112026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20231
2024none
20252
20261

Used in ransomware

Changes CISA made to these entries

  1. CVE-2025-61884 Oracle E-Business SuiteRansomware use: Unknown to Known.
  2. CVE-2025-61882 Oracle E-Business SuiteRansomware use: Unknown to Known.
  3. CVE-2025-61882 Oracle E-Business SuiteDeadline moved from 28 October 2025 to 27 October 2025. Listing date changed from 7 October 2025 to 6 October 2025.

Every change we recorded