Critical SAP Vulns Under Exploitation in 'One-Two Punch' Attack
ID: 9dd39e43-9174-5d92-9237-89ca2030d762
STIX ID: report--9dd39e43-9174-5d92-9237-89ca2030d762
Feed Name: Dark Reading
Threat Score
Two critical SAP NetWeaver Visual Composer vulnerabilities (CVE-2025-31324 and CVE-2025-42999) have been chained into a deserialization exploit that can yield remote code execution and full system takeover; the exploit was published on threat-actor channels and VX-Underground and is reported to be actively exploited. Organizations should apply SAP Security Note 3594142 and Security Note 3604119 to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
