Back to blog
CVERansomwareSupply chain

Oracle E-Business Suite CVE-2025-61882: Cl0p hits Michelin and 100+ companies in MOVEit's wake

Published on 2026-09-087 min readCleanIssue

> In short: The Cl0p extortion group exploited a critical zero-day (CVE-2025-61882, CVSS 9.8, pre-authentication RCE) in Oracle E-Business Suite (versions 12.2.3 to 12.2.14), the enterprise resource planning suite used by thousands of companies for ERP, HR, finance, and supply chain operations. Exploitation began as early as July 2025, but the campaign only became public in October 2025, when Oracle shipped an emergency out-of-band patch. More than 100 organizations are confirmed affected: French tire manufacturer Michelin (300GB of internal files claimed), plus Harvard University, the Washington Post, Logitech, Cox Enterprises, Envoy Air (an American Airlines subsidiary), Schneider Electric, Allianz UK, Emerson, and GlobalLogic (Hitachi). CISA added the flaw to its Known Exploited Vulnerabilities catalog.

MOVEit's playbook, replayed at ERP scale

The modus operandi directly echoes Cl0p's 2023 campaign against MOVEit Transfer (2,500+ companies hit): a single zero-day in a widely deployed enterprise application, silent exploitation for months before public disclosure, then mass extortion based on data theft rather than classic ransomware encryption. The difference this time: the target isn't a peripheral file-transfer tool, but Oracle E-Business Suite itself — the core information system of many large enterprises, with direct access to HR, finance, and supply-chain data.

The attack chained several server-side techniques to achieve unauthenticated remote code execution, using fileless malware to evade traditional detection. The most exposed components were publicly reachable EBS instances, particularly those with BI Publisher or Concurrent Processing integrations enabled.

Michelin: a representative example of the real-world impact

Michelin confirmed the compromise in March 2026, with over 300GB of internal files claimed by Cl0p — documents related to manufacturing, engineering, supply chain, finance, and HR. The company states the compromised data covers only a localized scope and doesn't include critical technical or system information. This kind of communication — minimize without denying — has become standard after this type of incident, and illustrates how hard it is to precisely gauge the real scale of a leak until the data is published or analyzed by third parties.

Why ERPs are such high-value targets

An ERP like Oracle E-Business Suite centralizes, by design, an organization's most sensitive data: payslips, supplier contracts, consolidated financial data, named HR records. A single pre-authentication vulnerability in this kind of system gives an attacker direct access to the heart of the enterprise — no need to compromise multiple separate systems. This explains why a handful of ERP zero-days (Oracle EBS, SAP, MOVEit) is enough to generate dozens or even hundreds of victims in a single campaign.

What organizations running Oracle EBS should do

  • Patch immediately if not already done: Oracle's emergency fix covers CVE-2025-61882 for all versions 12.2.3 through 12.2.14.
  • Assume potential compromise if your EBS instance was publicly exposed between July and October 2025, even without visible signs of intrusion: exploitation preceded public disclosure by several months.
  • Audit access logs for the BI Publisher and Concurrent Processing components, the most frequently targeted in this campaign.
  • Reduce the ERP's public exposure: a system handling HR, finance, and supply-chain data should never be directly reachable from the internet without strong authentication and strict network filtering upstream.
  • The lesson for HR and payroll SaaS vendors

    If your platform integrates with a client's ERP (payroll export, HR sync, financial data flows), this incident is a reminder that the security of your integrations also depends on the system you exchange data with. An audit that only covers your own application perimeter without questioning ERP integration points leaves exactly the kind of blind spot exploited here.

    Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Need an external review of your HR SaaS?

    Share your product, stack, and client context. We will come back with the right review scope.

    Discuss your audit