SAP NetWeaver Visual Composer exploitation campaign (Campaign)
ID: f6c7f5bf-9a17-5ccc-8280-11fe5293265e
STIX ID: report--f6c7f5bf-9a17-5ccc-8280-11fe5293265e
Feed Name: Wiz Cloud Threat Landscape
Threat Score
Date Published: 2025-04-22
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
...
...
Active exploitation of a critical SAP NetWeaver Visual Composer zero-day (CVE-2025-31324, CVSS 10.0) allowed unauthenticated RCE via the Metadata Uploader; attackers uploaded webshells (e.g., helper.jsp, cache.jsp), achieved system-level access using the <sid>adm account, and some systems were later re-used by opportunistic actors (cryptominers).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
