logo

SAP fixes suspected Netweaver zero-day exploited in attacks

ID: 920e694a-ca44-5527-8e57-c9f6a5613b07

STIX ID: report--920e694a-ca44-5527-8e57-c9f6a5613b07

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-04-25

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

SAP released an out-of-band emergency patch for a critical unauthenticated file-upload vulnerability (CVE-2025-31324, CVSS 10.0) in NetWeaver Visual Composer's Metadata Uploader that is being actively exploited in the wild to upload JSP webshells and achieve remote code execution; multiple security firms (ReliaQuest, Onapsis, watchTowr) reported customer compromises and observed post-exploitation tools and techniques. Organizations are advised to apply the emergency update immediately, restrict access to the /developmentserver/metadatauploader endpoint, disable Visual Composer if unused, forward logs to SIEM, and scan for unauthorized files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.