logo

Patch Tuesday (Expel’s version): May 2025

ID: d5edd4d3-f9a2-5623-be25-3bd13843918d

STIX ID: report--d5edd4d3-f9a2-5623-be25-3bd13843918d

Feed Name: Expel Blog

Threat Score
90/100

Date Published: 2025-05-13

Date Updated: 2026-04-27

Author: Ben Nahorney; Matt Jastram

...
...

This Patch Tuesday briefing summarizes Microsoft’s May 13, 2025 updates and calls out multiple critical and exploited vulnerabilities, with particular emphasis on CVE-2025-31324 in SAP NetWeaver — a trivial arbitrary file upload that has been actively exploited to deploy webshells (CVSS 10) and included in CISA’s KEV catalog; the report details observed post-exploitation commands, available YARA/IOC scanners, and urges immediate patching and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.