Estée Lauder confirmed it experienced a data breach linked to an Oracle E-Business Suite vulnerability, with the incident occurring in August 2025 but disclosed only in June 2026. The company stated that attackers accessed personal information through an unauthorized entry into its HR management platform.
The breach, attributed to the exploitation of CVE-2025-61882, a critical remote code execution flaw, compromised extensive data. Affected individuals had their full names, postal addresses, email addresses, dates of birth, Social Security numbers, passport numbers, financial account information, health information, and employment details stolen.
The exact number of individuals impacted remains unknown. Estée Lauder’s notification, sent to clients, revealed that the breach was discovered during an investigation initiated on June 19, 2026.
This incident is part of a broader wave of attacks exploiting the Oracle E-Business Suite, which began in October 2025. More than 100 organizations reported similar breaches, prompting Oracle to issue an emergency patch for the vulnerability shortly thereafter.
Oracle characterized the flaw as remotely exploitable without authentication, allowing attackers to execute commands on affected systems. The company addressed the severity of the vulnerability, which scored 9.8 out of 10 on the critical scale.




