Oracle E-Business Suite CVE-2025-61882: Cl0p hits Michelin and 100+ companies in MOVEit's wake
> In short: The Cl0p extortion group exploited a critical zero-day (CVE-2025-61882, CVSS 9.8, pre-authentication RCE) in Oracle E-Business Suite (versions 12.2.3 to 12.2.14), the enterprise resource planning suite used by thousands of companies for ERP, HR, finance, and supply chain operations. Exploitation began as early as July 2025, but the campaign only became public in October 2025, when Oracle shipped an emergency out-of-band patch. More than 100 organizations are confirmed affected: French tire manufacturer Michelin (300GB of internal files claimed), plus Harvard University, the Washington Post, Logitech, Cox Enterprises, Envoy Air (an American Airlines subsidiary), Schneider Electric, Allianz UK, Emerson, and GlobalLogic (Hitachi). CISA added the flaw to its Known Exploited Vulnerabilities catalog.
MOVEit's playbook, replayed at ERP scale
The modus operandi directly echoes Cl0p's 2023 campaign against MOVEit Transfer (2,500+ companies hit): a single zero-day in a widely deployed enterprise application, silent exploitation for months before public disclosure, then mass extortion based on data theft rather than classic ransomware encryption. The difference this time: the target isn't a peripheral file-transfer tool, but Oracle E-Business Suite itself — the core information system of many large enterprises, with direct access to HR, finance, and supply-chain data.
The attack chained several server-side techniques to achieve unauthenticated remote code execution, using fileless malware to evade traditional detection. The most exposed components were publicly reachable EBS instances, particularly those with BI Publisher or Concurrent Processing integrations enabled.
Michelin: a representative example of the real-world impact
Michelin confirmed the compromise in March 2026, with over 300GB of internal files claimed by Cl0p — documents related to manufacturing, engineering, supply chain, finance, and HR. The company states the compromised data covers only a localized scope and doesn't include critical technical or system information. This kind of communication — minimize without denying — has become standard after this type of incident, and illustrates how hard it is to precisely gauge the real scale of a leak until the data is published or analyzed by third parties.
Why ERPs are such high-value targets
An ERP like Oracle E-Business Suite centralizes, by design, an organization's most sensitive data: payslips, supplier contracts, consolidated financial data, named HR records. A single pre-authentication vulnerability in this kind of system gives an attacker direct access to the heart of the enterprise — no need to compromise multiple separate systems. This explains why a handful of ERP zero-days (Oracle EBS, SAP, MOVEit) is enough to generate dozens or even hundreds of victims in a single campaign.
What organizations running Oracle EBS should do
The lesson for HR and payroll SaaS vendors
If your platform integrates with a client's ERP (payroll export, HR sync, financial data flows), this incident is a reminder that the security of your integrations also depends on the system you exchange data with. An audit that only covers your own application perimeter without questioning ERP integration points leaves exactly the kind of blind spot exploited here.
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
MOVEit 2023: How Cl0p Exploited a Zero-Day to Hit 2,500+ Companies
Technical analysis of the Cl0p campaign against MOVEit Transfer in 2023: the SQLi vulnerability, exploitation chain, and lessons.
Cl0p + PTC Windchill/FlexPLM CVE-2026-12569: a ransomware chain on enterprise PLM
Cl0p affiliates are chaining a pre-auth info-disclosure in FlexPLM's WSDL with a server-side flaw in the Windchill login servlet for unauthenticated RCE (CVE-2026-12569, CVSS 9.3) on internet-exposed PTC instances, deploying JSP webshells and staging engineering data for double extortion.
CEVA Logistics 2026: ransomware paralyzes 8 European warehouses and exposes major clients' data
Between July 29 and August 1, 2026, the logistics arm of French shipping group CMA CGM suffered a ransomware attack that shut down eight European warehouses. Contact details, orders, and VAT numbers of clients including Valve, Bol.com, and ING were exfiltrated; class-action lawsuits followed in the US.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.