CISA Sounds the Alarm: Five New Critical Vulnerabilities Added to the KEV Catalog

Listen to this Post

Featured Image
In a world where cyberattacks evolve faster than most companies can patch, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has once again updated its Known Exploited Vulnerabilities (KEV) Catalog, a public list of security flaws actively used by attackers worldwide. This week, five new vulnerabilities have been added — and they’re not just any bugs. Among them is a critical remote code execution (RCE) flaw in Oracle E-Business Suite, tracked as CVE-2025-61884, that’s already being exploited in the wild.

The addition of these vulnerabilities underscores an unsettling truth: enterprise systems remain lucrative targets, and attackers are moving swiftly to weaponize weaknesses in widely used software. According to the brief report shared by Cybersecurity News Everyday (@TweetThreatNews), the new entries in the KEV catalog include flaws not only in Oracle products but also in Microsoft technologies, signaling a multi-front assault against some of the world’s most essential business platforms.

The Summary: Why This Matters

CISA’s KEV Catalog is essentially a government-maintained “must-patch” list — vulnerabilities confirmed to be actively exploited by hackers. When new bugs appear on it, it’s a warning shot to all federal agencies and private-sector entities: patch now or risk compromise.

This latest update includes five new exploited vulnerabilities, the most alarming of which is CVE-2025-61884, a remote code execution flaw in Oracle’s E-Business Suite (EBS). The EBS is a widely deployed platform used by corporations for financials, supply chain, and HR operations. Exploiting this flaw allows attackers to run arbitrary code on targeted servers, potentially giving them full control over sensitive enterprise environments.

The report also mentions Microsoft products as part of the affected list. While exact CVE numbers weren’t disclosed in the tweet, experts speculate that the exploited vulnerabilities could be tied to Office 365 or Windows Server components, given recent exploit trends seen in phishing and lateral movement campaigns.

In response, CISA has instructed federal agencies to apply necessary patches immediately, as part of its binding operational directive that mandates remediation within specific time frames. This ensures that U.S. government networks remain resilient against active exploitation.

Security analysts highlight that the addition of Oracle and Microsoft vulnerabilities to the same KEV update signals an aggressive, coordinated wave of exploitation—possibly tied to ransomware affiliates or state-sponsored groups. Both platforms power critical infrastructure and corporate backbones, making them prime targets for large-scale cyberattacks.

Oracle, for its part, has released patches for CVE-2025-61884 in its latest Critical Patch Update, urging customers to deploy it without delay. Microsoft’s patching cadence, aligned with its regular “Patch Tuesday” schedule, also includes fixes for high-severity vulnerabilities recently seen in active campaigns.

What’s most concerning is that these exploits appear to be leveraged against live production systems, meaning attackers are no longer testing—they’re already executing. Once a vulnerability reaches the KEV list, it’s no longer theoretical; it’s confirmed active in the real world.

The ongoing trend suggests that threat actors are focusing more on supply chain software and enterprise management platforms, systems that hold the keys to thousands of connected business environments. The Oracle EBS flaw, in particular, could have downstream effects across vendors and partners who rely on shared data structures.

Ultimately, the message from CISA is loud and clear: these are not optional updates. Every organization running Oracle or Microsoft software must treat this alert as an emergency patching event, not a routine update cycle.

What Undercode Say:

When CISA updates its KEV Catalog, it’s not just bureaucracy — it’s a glimpse into the live battlefield of cybersecurity. The inclusion of Oracle’s E-Business Suite in the latest list is especially concerning because it bridges both legacy enterprise systems and modern interconnected ecosystems.

This particular RCE flaw (CVE-2025-61884) exposes a deep-rooted vulnerability in how organizations maintain critical ERP systems. These aren’t consumer tools; they’re the central nervous systems of corporations, often managing billions in financial transactions and human resource data. A successful exploit here could mean total data compromise — payroll records, procurement data, and intellectual property all at risk.

From an analytical standpoint, Oracle’s EBS platforms are notorious for being difficult to update. Many organizations postpone patches due to operational complexity, compatibility issues, or the fear of downtime. That delay creates the perfect attack window for adversaries. It’s the same old story: attackers move fast, defenders hesitate.

The inclusion of Microsoft vulnerabilities amplifies the scope. Attackers aren’t picking sides — they’re exploiting ecosystem dependencies. For instance, a compromise in an EBS system can be leveraged to move laterally into connected Microsoft domains, exfiltrating credentials or launching ransomware payloads.

CISA’s proactive publication of these CVEs is a positive step, but the deeper issue remains patch fatigue. Many security teams are overwhelmed by the relentless pace of vulnerability disclosures, leading to selective patching rather than holistic remediation.

From a broader cybersecurity policy view, this also reveals how vital cross-industry collaboration has become. Oracle, Microsoft, and federal agencies must coordinate not just on patching, but on early detection and exploit telemetry. Sharing threat intelligence in near real-time could reduce the lag between discovery and mitigation — a lag attackers exploit ruthlessly.

It’s also worth noting that CVE-2025-61884 joins a growing list of supply-chain-related attack vectors. Oracle’s EBS integrates with numerous third-party solutions — payroll, logistics, accounting — and every integration is another potential pivot point for attackers. The blast radius isn’t limited to one enterprise; it’s systemic.

From an undercode perspective, this incident should be a wake-up call to corporate cybersecurity maturity. Organizations need not just patch management but cyber hygiene discipline, including configuration hardening, zero-trust enforcement, and active threat hunting.

CISA’s warning signals an undeniable reality: defenders can no longer wait for quarterly patch cycles. Threat actors are treating vulnerabilities as fresh opportunities in real time, and the only sustainable defense is continuous adaptation.

The takeaway? Patch now, verify, and monitor. The attackers already have a head start.

Fact Checker Results:

✅ CISA has officially added CVE-2025-61884 (Oracle E-Business Suite RCE) to the KEV Catalog.
✅ The vulnerability is confirmed to be under active exploitation.
❌ No confirmed link yet between this Oracle exploit and specific threat actor groups.

Prediction:

🛡️ Expect a surge in phishing campaigns and ransomware incidents leveraging Oracle EBS and Microsoft exploits within the next few weeks.
📉 Organizations that delay patching could face operational disruptions or data leaks by Q4 2025.
📈 Vendors will likely accelerate automated patch delivery and AI-driven vulnerability scanning to counteract faster exploit cycles.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon