Drooid Logo
Back to story perspectives

Full Breakdown

CISA Flags Critical Vulnerabilities in Oracle and Microsoft Products

10/21/2025, 11:03:29 AM

Overview of Newly Identified Vulnerabilities

On October 20, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, highlighting significant security risks in widely used software from Oracle, Microsoft, and Apple. Among these, the most pressing is CVE-2025-61884, a server-side request forgery (SSRF) vulnerability in Oracle E-Business Suite, which has been confirmed as actively exploited in real-world attacks.

Details of the Vulnerabilities

CVE-2025-61884, with a CVSS score of 7.5, allows attackers to exploit the Runtime component of Oracle Configurator without requiring authentication, posing a severe threat to organizations using this enterprise resource planning software. This vulnerability is particularly dangerous as it enables unauthorized access to sensitive data and could facilitate deeper network penetration.

In addition to the Oracle vulnerability, CISA flagged four other vulnerabilities:

  • CVE-2022-48503: An improper validation of array index vulnerability in Apple's JavaScriptCore component (CVSS score: 8.8) that could lead to arbitrary code execution.

Active Exploitation and Threat Landscape

The vulnerabilities, particularly CVE-2025-61884 and CVE-2025-61882 (a critical remote code execution flaw also in Oracle EBS), have been linked to the CL0P ransomware group, which has reportedly targeted numerous organizations, including Harvard University and American Airlines' Envoy Air subsidiary. Security experts have noted that the exploitation of these vulnerabilities could lead to significant data breaches and extortion attempts.

CISA has mandated that federal civilian executive branch agencies remediate these vulnerabilities by November 10, 2025, to protect their networks against these active threats. Organizations unable to apply the necessary patches are advised to discontinue the use of affected products until proper protections are implemented.

Official Statements & Responses

CISA emphasized the urgency of addressing these vulnerabilities, stating, "Organizations should follow applicable BOD 22-01 guidance for cloud services and coordinate with Oracle to obtain the latest security updates addressing this critical flaw." The agency's alert underscores the importance of maintaining current patch levels and implementing defense-in-depth strategies to safeguard against emerging threats.

Criticism & Opposition

While CISA has not confirmed whether these vulnerabilities have been weaponized in ransomware campaigns, the lack of detailed information on the exploitation methods has raised concerns among cybersecurity professionals. Some experts argue that more transparency is needed regarding the specific tactics employed by threat actors to exploit these vulnerabilities.

Verbatim Quotes

  • “This vulnerability is remotely exploitable without authentication,” — CISA
  • “This represents a quintessential elevation-of-privilege vector that exploits default configurations,” — Maria Gonzalez, Cybersecurity Analyst at SentinelOne

What's Next

Organizations are urged to prioritize patching efforts and conduct thorough security assessments to identify any indicators of compromise. As the deadline approaches, the focus remains on enhancing defenses against the evolving landscape of cyber threats, particularly those targeting critical infrastructure and enterprise applications.