Oracle had five vulnerabilities confirmed exploited over the past year across PeopleSoft, Fusion Middleware, E-Business Suite, and WebLogic Server — and three of the five carry CISA's confirmed ransomware campaign flag, an unusually high concentration for a single vendor's cluster in this series.
| CVE | CVSS | Product | Ransomware use |
|---|---|---|---|
| CVE-2026-35273 | 9.8 | PeopleSoft Enterprise PeopleTools | Known |
| CVE-2025-61882 | 9.8 | E-Business Suite | Known |
| CVE-2025-61884 | 7.5 | E-Business Suite | Known |
| CVE-2025-61757 | 9.8 | Fusion Middleware (Identity Manager) | Unknown |
| CVE-2024-21182 | 7.5 | WebLogic Server | Unknown |
Why three-of-five with confirmed ransomware use is worth stating plainly
Across every vendor cluster covered in this series, a confirmed ransomware flag on even one CVE has been treated as a signal deserving elevated priority. Oracle's cluster carries that flag on three separate findings spanning two different product lines — PeopleSoft and E-Business Suite — which is a materially different risk picture than a single confirmed-ransomware finding in isolation. It suggests ransomware operators have specifically identified Oracle's large enterprise application platforms as productive targets, not that one opportunistic campaign happened to hit one Oracle product once.
PeopleSoft and E-Business Suite are both large-scale enterprise resource planning platforms handling core business functions — human resources, financials, supply chain — for the organizations running them, frequently for decades given how deeply embedded these systems become in an organization's operations. That combination of high organizational dependency and now-demonstrated ransomware interest is exactly the profile that should move Oracle ERP patch currency to the top of a security team's list, independent of any single CVE's own severity score.
Why E-Business Suite's two CVEs deserve reading together
CVE-2025-61882 and CVE-2025-61884 both affect E-Business Suite and both carry the confirmed ransomware flag — a similar pattern to the SonicWall and SharePoint clusters covered elsewhere in this series, where two related findings in the same product, confirmed for the same malicious use, suggest a single campaign or toolkit exploiting more than one weakness in the same target.
What to check this week
Treat any unpatched Oracle E-Business Suite or PeopleSoft deployment as an active incident-response priority, not a routine patch item, given the confirmed ransomware association on three separate findings across these two product lines.
Audit ERP system backups and their isolation from the production environment specifically. Ransomware targeting core ERP platforms follows the same playbook seen elsewhere in this series against virtualization and PLM infrastructure — encrypting both production systems and any insufficiently isolated backup simultaneously.
Apply the same urgency to Fusion Middleware Identity Manager and WebLogic Server patching, even absent a confirmed ransomware flag on those two specifically — an unconfirmed association today doesn't preclude one tomorrow, and both carry serious standalone severity.
Why long-tenured ERP deployments compound the risk
Organizations frequently run the same Oracle ERP instance, with customizations and integrations built up over many years, well past the point where a straightforward version upgrade is a simple undertaking — heavily customized instances are exactly where patch application gets deferred longest, because a security update carries real risk of breaking accumulated custom code. That operational reality is precisely why a confirmed ransomware association against these platforms specifically should override the usual deference to a slower, more cautious ERP patch cycle.
A closing note on third-party managed Oracle deployments
Organizations running Oracle ERP through a managed hosting or systems-integrator relationship should confirm directly, in writing, who holds responsibility for applying these specific patches — a gap in that responsibility split is a common and entirely avoidable reason a known, confirmed-exploited vulnerability goes unaddressed.
A final consideration on cyber insurance implications
Organizations holding cyber insurance policies should review whether an unpatched, confirmed-exploited, confirmed-ransomware-associated vulnerability like the three covered here could affect a claim's outcome — many policies carry specific language conditioning coverage on maintaining reasonable patching practices against known, actively exploited findings.
How Safeguard helps
Safeguard's continuous inventory tracks a vendor's full portfolio of confirmed-exploited and ransomware-associated findings together, surfacing exactly the kind of concentrated, multi-product risk pattern this Oracle cluster represents — the difference between seeing five separate, seemingly disconnected advisories and recognizing a single vendor relationship that now warrants materially elevated security attention.