Patch Tuesday (Expel’s version): May 2025
ID: d5edd4d3-f9a2-5623-be25-3bd13843918d
STIX ID: report--d5edd4d3-f9a2-5623-be25-3bd13843918d
Feed Name: Expel Blog
Threat Score
This Patch Tuesday briefing summarizes Microsoft’s May 13, 2025 updates and calls out multiple critical and exploited vulnerabilities, with particular emphasis on CVE-2025-31324 in SAP NetWeaver — a trivial arbitrary file upload that has been actively exploited to deploy webshells (CVSS 10) and included in CISA’s KEV catalog; the report details observed post-exploitation commands, available YARA/IOC scanners, and urges immediate patching and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
