logo

Critical, make-me-super-user SAP S/4HANA bug under active exploitation

ID: 8a95b936-a806-5044-a5d3-ef53cdfd693a

STIX ID: report--8a95b936-a806-5044-a5d3-ef53cdfd693a

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-09-05

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A critical 9.9-rated code-injection vulnerability (CVE-2025-42957) in SAP S/4HANA enables low-privileged attackers to inject ABAP code, bypass authorizations, and create SAP_ALL superuser accounts; SecurityBridge verified active exploitation and SAP issued an August patch. Apply the update immediately, consider restricting RFC usage and S_DMIS activity 02, and monitor for suspicious RFC calls, newly created admin users, and ABAP code changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.