SAP patches second zero-day flaw exploited in recent attacks
ID: 1ee15e7e-eade-51b0-ab1d-c86a71b0b939
STIX ID: report--1ee15e7e-eade-51b0-ab1d-c86a71b0b939
Feed Name: Bleeping Computer
**SAP NetWeaver zero-day exploitation and patch advisory** — Multiple SAP NetWeaver vulnerabilities (notably CVE-2025-31324 and CVE-2025-42999) have been exploited in the wild to upload JSP web shells and tools like Brute Ratel; numerous exposed and compromised instances — including large enterprises — were observed, attribution links some activity to a Chinese actor (Chaya_004), and CISA added the issue to its Known Exploited Vulnerabilities catalog while SAP released patches and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
