If you read nothing else
- Patch Oracle E-Business Suite now if you run it. CISA lists CVE-2025-61882 as exploited, and the flaw affects versions 12.2.3 through 12.2.14.
- If you ever used SonicWall cloud backup, assume your firewall configuration was copied and reset your admin passwords.
- Treat every CISA deadline as the clock for your own patching, not just the federal one.
Four things from the week of October 6 to October 12, 2025. Three come from CISA's exploited-vulnerability list and one from a firewall vendor's update.
1. CISA added the Oracle E-Business Suite flaw on October 6
CISA added CVE-2025-61882, an Oracle E-Business Suite flaw, to its Known Exploited Vulnerabilities catalog on October 6, with October 27 as the federal patch deadline. The flaw affects versions 12.2.3 through 12.2.14. Source: CISA KEV feed; Help Net Security, October 6.
What this means for you: an exploited flaw in a finance system is a data-theft risk, not just a patch ticket.
Do this: confirm this week that any Oracle E-Business Suite instance you rely on is on a patched version, and keep the answer in writing.
2. SonicWall says every cloud backup customer's firewall files were accessed
On Wednesday, October 8, SonicWall said attackers accessed the configuration backup files of all customers who had used its cloud backup service. On September 17 it had said fewer than 5% of its firewall install base was affected. Source: Help Net Security, October 9.
What this means for you: firewall configuration files show how your network is built, which helps an attacker plan the next step.
Do this: if you ever used SonicWall cloud backup, reset your firewall admin passwords and review the saved configuration with your IT provider.
3. Two more flaws joined the exploited list
On October 7, CISA added a cross-site scripting flaw in Synacor Zimbra Collaboration Suite (CVE-2025-27915), with an October 28 federal deadline. On October 9, it added a path traversal flaw in Grafana (CVE-2021-43798), with an October 30 deadline. Source: CISA KEV feed.
What this means for you: mail and dashboard servers sit on the internet and are often missed in patch cycles.
Do this: list every mail and dashboard server you run, and confirm each one's version and last patch date.
4. Windows and Linux kernel flaws from 2021 were added on October 6
On October 6, CISA added a 2021 Windows privilege escalation flaw (CVE-2021-43226) and a 2021 Linux kernel heap flaw (CVE-2021-22555) to its catalog. Source: CISA KEV feed.
What this means for you: old flaws stay in use, so a fully patched year does not mean you are clear.
Do this: confirm that every Windows and Linux system on your network still receives updates, and retire any machine too old to get them.
Not sure where you stand? Cyber Grants Alliance offers in-kind CMMC Level 1 and CMMC Level 2 gap assessment grants, at no cost to you, to show where your gaps are. See every program on Grant Programs.
