Over 900 Oracle E-Business instances exposed to ongoing attacks
Over 900 internet-exposed Oracle E-Business Suite instances are being actively targeted in ongoing attacks. The attacks exploit vulnerabilities, including CVE-2022-21587 and a newly discovered one, to steal data or deploy malware. Organizations are urged to patch affected systems immediately.
Background
- Oracle E-Business Suite (EBS) is a popular enterprise resource planning (ERP) software package used by large organizations worldwide to manage finance, supply chain, HR, and operations. It's often called "Oracle EBS" or simply "E-Biz."
- Researchers found that over 900 internet-facing Oracle EBS servers are exposed (i.e., accessible from the public web without proper isolation), making them vulnerable to ongoing attacks.
- Attackers are actively targeting a recently disclosed vulnerability (CVE-2025-30262, among others) that allows unauthenticated remote code execution — meaning a hacker can take full control of the system without needing a password.
- Because EBS systems handle sensitive corporate and financial data, this is a serious security risk. Organizations running Oracle EBS are urged to check if their instance is exposed and apply the latest security patches from Oracle.