{"id":240487,"date":"2025-10-21T07:31:14","date_gmt":"2025-10-21T07:31:14","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/240487\/"},"modified":"2025-10-21T07:31:14","modified_gmt":"2025-10-21T07:31:14","slug":"five-new-exploited-bugs-land-in-cisas-catalog-oracle-and-microsoft-among-targets","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/240487\/","title":{"rendered":"Five New Exploited Bugs Land in CISA&#8217;s Catalog \u2014 Oracle and Microsoft Among Targets"},"content":{"rendered":"<p>\ue802Oct 20, 2025\ue804Ravie LakshmananThreat Intelligence \/ Data Security<\/p>\n<p><a href=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/10\/CISA.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/10\/CISA.jpg\" alt=\"\" border=\"0\" data-original-height=\"470\" data-original-width=\"900\"\/><\/a><\/p>\n<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/10\/20\/cisa-adds-five-known-exploited-vulnerabilities-catalog\" rel=\"noopener nofollow\" target=\"_blank\">added<\/a> five security flaws to its Known Exploited Vulnerabilities (<a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" rel=\"noopener nofollow\" target=\"_blank\">KEV<\/a>) Catalog, officially confirming a recently disclosed vulnerability impacting Oracle E-Business Suite (EBS) has been weaponized in real-world attacks.<\/p>\n<p>The security defect in question is <a href=\"https:\/\/thehackernews.com\/2025\/10\/new-oracle-e-business-suite-bug-could.html\" rel=\"noopener nofollow\" target=\"_blank\">CVE-2025-61884<\/a> (CVSS score: 7.5), which has been described as a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator that could allow attackers unauthorized access to critical data.<\/p>\n<p>&#8220;This vulnerability is remotely exploitable without authentication,&#8221; CISA said.<\/p>\n<p><a href=\"https:\/\/thehackernews.uk\/cloud-insight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"DFIR Retainer Services\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/10\/cloud-insight-d.png\" width=\"729\" height=\"91\"\/><\/a><\/p>\n<p>CVE-2025-61884 is the second flaw in Oracle EBS to be actively exploited along with <a href=\"https:\/\/thehackernews.com\/2025\/10\/oracle-rushes-patch-for-cve-2025-61882.html\" rel=\"noopener nofollow\" target=\"_blank\">CVE-2025-61882<\/a> (CVSS score: 9.8), a critical bug that could permit unauthenticated attackers to execute arbitrary code on susceptible instances.<\/p>\n<p>Earlier this month, Google Threat Intelligence Group (GTIG) and Mandiant <a href=\"https:\/\/thehackernews.com\/2025\/10\/cl0p-linked-hackers-breach-dozens-of.html\" rel=\"noopener nofollow\" target=\"_blank\">revealed<\/a> dozens of organizations may have been impacted following the exploitation of CVE-2025-61882.<\/p>\n<p>&#8220;At this time, we are not able to attribute any specific exploitation activity to a specific actor, but it&#8217;s likely that at least some of the exploitation activity we observed was conducted by actors now conducting Cl0p-branded extortion operations,&#8221; Zander Work, senior security engineer at GTIG, told The Hacker News last week.<\/p>\n<p>Also added by CISA to the KEV catalog are four other vulnerabilities &#8211;<\/p>\n<p><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-33073\" rel=\"noopener nofollow\" target=\"_blank\">CVE-2025-33073<\/a> (CVSS score: 8.8) &#8211; An improper access control vulnerability in Microsoft Windows SMB Client that could allow for privilege escalation (Fixed by Microsoft in June 2025)<br \/>\n<a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-2746\" rel=\"noopener nofollow\" target=\"_blank\">CVE-2025-2746<\/a> (CVSS score: 9.8) &#8211; An authentication bypass using an alternate path or channel vulnerability in Kentico Xperience CMS that could allow an attacker to control administrative objects by taking advantage of the Staging Sync Server password handling of empty SHA1 usernames in digest authentication (Fixed in Kentico in March 2025)<br \/>\n<a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-2747\" rel=\"noopener nofollow\" target=\"_blank\">CVE-2025-2747<\/a> (CVSS score: 9.8) &#8211; An authentication bypass using an alternate path or channel vulnerability in Kentico Xperience CMS that could allow an attacker to control administrative objects by taking advantage of the Staging Sync Server password handling for the server defined None type (Fixed in Kentico in March 2025)<br \/>\n<a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-48503\" rel=\"noopener nofollow\" target=\"_blank\">CVE-2022-48503<\/a> (CVSS score: 8.8) &#8211; An improper validation of array index vulnerability in Apple&#8217;s JavaScriptCore component that could result in arbitrary code execution when processing web content (Fixed by Apple in July 2022)<\/p>\n<p><a href=\"https:\/\/thehackernews.uk\/platform-shield-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"CIS Build Kits\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/10\/cis-d.png\" width=\"729\" height=\"91\"\/><\/a><\/p>\n<p>There are currently no details on how the aforementioned four issues are being exploited in the wild, although details about CVE-2025-33073, CVE-2025-2746, and CVE-2025-2747 were shared by researchers from <a href=\"https:\/\/thehackernews.com\/2025\/06\/microsoft-patches-67-vulnerabilities.html\" rel=\"noopener nofollow\" target=\"_blank\">Synacktiv<\/a> and <a href=\"https:\/\/thehackernews.com\/2025\/04\/weekly-recap-critical-sap-exploit-ai.html#:~:text=New%20Flaws%20in%20Kentico%20Xperience%20CMS\" rel=\"noopener nofollow\" target=\"_blank\">watchTowr Labs<\/a>, respectively.<\/p>\n<p>Federal Civilian Executive Branch (FCEB) agencies are required to remediate identified vulnerabilities by November 10, 2025, to secure their networks against active threats.<\/p>\n","protected":false},"excerpt":{"rendered":"\ue802Oct 20, 2025\ue804Ravie LakshmananThreat Intelligence \/ Data Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday&hellip;\n","protected":false},"author":2,"featured_media":240488,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[5407,5400,5393,5392,5394,5395,5396,5401,5397,5398,5403,5405,5404,5402,5399,74,5406],"class_list":["post-240487","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-computer-security","tag-cyber-attacks","tag-cyber-news","tag-cyber-security-news","tag-cyber-security-news-today","tag-cyber-security-updates","tag-cyber-updates","tag-data-breach","tag-hacker-news","tag-hacking-news","tag-how-to-hack","tag-information-security","tag-network-security","tag-ransomware-malware","tag-software-vulnerability","tag-technology","tag-the-hacker-news"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/240487","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=240487"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/240487\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/240488"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=240487"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=240487"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=240487"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}