Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

NCSC Warns of Oracle E-Business Suite 0-Day Vulnerability Actively Exploited in Attacks

The National Cyber Security Centre (NCSC) has issued an urgent warning about a critical zero-day vulnerability identified in Oracle E-Business Suite (EBS) . This flaw is actively exploited in the wild.

The National Cyber Security Centre (NCSC) has issued an urgent warning about a critical zero-day vulnerability identified in Oracle E-Business Suite (EBS) . This flaw is actively exploited in the wild.

The vulnerability, tracked as CVE-2025-61882 , exists in the BI Publisher Integration component of Oracle Concurrent Processing. It facilitates unauthenticated remote code execution.

Organizations using EBS versions 12.2.3 through 12.2.14, especially those with internet exposure, are at significant risk.

Oracle BI Publisher Flaw (CVE-2025-61882)

Oracle's security alert indicates that attackers can send crafted HTTP requests to the BI Publisher Integration servlet without authentication, leading to full system compromise. No user interaction is necessary. Exploiting this vulnerability allows for arbitrary command execution, potentially resulting in data exfiltration, system takeover, or lateral movement within corporate networks.

Indicators of compromise (IoCs) include anomalous servlet URIs, unexpected child processes from $XBPSRV, and unusual outbound connections on non-standard ports. The NCSC is actively monitoring incidents and has observed multiple exploitation attempts against organizations in the UK.

Risk Factors Details

The vulnerability, tracked as CVE-2025-61882 , exists in the BI Publisher Integration component of Oracle Concurrent Processing.
Amanda Parks · Thehackingpost

Affected Products Oracle E-Business Suite (EBS) 12.2.3 – 12.2.14; BI Publisher Integration component

Impact Remote code execution (RCE)

Exploit Prerequisites Network access to exposed BI Publisher Integration endpoint; no authentication or user interaction required

CVSS 3.1 Score 9.8 (Critical)

To address CVE-2025-61882, the NCSC advises UK organizations to implement a defense-in-depth strategy. This includes applying Oracle's October 2023 Critical Patch Update and the specific EBS patch for CVE-2025-61882, as detailed in Oracle's advisory.

Advertisement

Organizations should use published IoCs to scan logs, web access records, and process listings for exploitation signs. Tools like grep and SIEM rules can assist in identifying suspicious activity.

To reduce risk, limit public exposure of Oracle EBS components. If internet access is necessary, implement web application firewalls (WAFs), strict access control lists (ACLs), and follow NCSC's network perimeter guidelines.

Deploy endpoint detection and response (EDR) agents on application servers and conduct behavioral analysis to detect unusual activities. If a compromise is suspected, report to Oracle PSIRT and the NCSC via its online portal for coordinated response and threat intelligence sharing.

The NCSC offers additional resources, including guidance on vulnerability management and the Early Warning service for real-time alerts. These measures will help strengthen the resilience of Oracle E-Business Suite against current and future vulnerabilities.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories