logo

SAP NetWeaver Visual Composer exploitation campaign (Campaign)

ID: f6c7f5bf-9a17-5ccc-8280-11fe5293265e

STIX ID: report--f6c7f5bf-9a17-5ccc-8280-11fe5293265e

Feed Name: Wiz Cloud Threat Landscape

Threat Score
90/100

Date Published: 2025-04-22

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Active exploitation of a critical SAP NetWeaver Visual Composer zero-day (CVE-2025-31324, CVSS 10.0) allowed unauthenticated RCE via the Metadata Uploader; attackers uploaded webshells (e.g., helper.jsp, cache.jsp), achieved system-level access using the <sid>adm account, and some systems were later re-used by opportunistic actors (cryptominers).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.