logo

Patch Tuesday: September 2025 (Expel’s version)

ID: d3ed6cdb-0014-59f1-96e5-c3c74d77daaf

STIX ID: report--d3ed6cdb-0014-59f1-96e5-c3c74d77daaf

Feed Name: Expel Blog

Threat Score
80/100

Date Published: 2025-09-09

Date Updated: 2026-04-27

Author: Ben Nahorney; Matt Jastram

...
...

This Patch Tuesday report (Sept 9, 2025) reviews 86 new CVEs (13 critical) and calls out urgent flaws to prioritize, with particular emphasis on SAP S/4HANA CVE-2025-42957 (code injection, CVSS 9.9) — reported in the wild and enabling full system takeover via the RFC interface — and NetWeaver CVE-2025-42944 (CVSS 10). The post recommends immediate patching and reducing public exposure of vulnerable administrative/RFC interfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.