The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle Fusion Middleware to its Known Exploited Vulnerabilities Catalog. The flaw, CVE-2025-61757, impacts the Identity Manager component and carries a CVSS score of 9.8, signifying that it is an easily exploitable issue that could allow an unauthenticated attacker to compromise and take over the component. Oracle first disclosed the vulnerability as part of its Critical Patch Update Advisory on October 21. According to the security firm that discovered it, exploitation of the flaw is likely “trivial”. The inclusion in CISA's catalog confirms that there are active, in-the-wild exploits of this vulnerability, raising the urgency for customers to apply security patches.
CISA Adds Critical Oracle Fusion Middleware Vulnerability to Known Exploited List
ORCL
Related News
ORCL
Developers Pressure Oracle to Cede Control of MySQL Amid AI-Era Stagnation Fears
ORCL
Oracle Stock Rises on Hedge Fund Buying and Tech Sector Recovery
ORCL
Oracle stock rises in pre-market trading amid broader tech recovery and upcoming earnings catalyst
ORCL
Oracle Shares Slide 3.9% as AI Debt and Fraud Lawsuits Cloud Growth Outlook
ORCL