CVE Tools
Back to feed
Exploited in the wild Oracle E-Business Suite Cl0p data-breach Oracle rce

Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

Cosmetics giant Estée Lauder has confirmed that sensitive employee data was stolen due to a zero-day vulnerability in Oracle E-Business Suite (CVE-2025-61882). The flaw allowed unauthenticated remote code execution and was exploited by the Cl0p cybercrime group starting in August 2025. In June 2026, the company revealed that personal and financial information of employees had been accessed, including names, Social Security numbers, and health records. Estée Lauder is offering two years of free identity monitoring to affected individuals and urging vigilance against phishing attempts.