Over 1,200 SAP NetWeaver servers vulnerable to actively exploited flaw
ID: 3c0993b2-1924-5e98-a154-6a4e682f8f82
STIX ID: report--3c0993b2-1924-5e98-a154-6a4e682f8f82
Feed Name: Bleeping Computer
Threat Score
**Active exploitation of SAP NetWeaver CVE-2025-31324:** An unauthenticated file-upload flaw in the Visual Composer Metadata Uploader allows remote code execution and full system compromise; security firms report hundreds to over a thousand internet-exposed NetWeaver instances (with hundreds already hosting webshells), affecting large enterprises and prompting SAP mitigations and a security update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
