logo

Threat Brief: CVE-2025-31324 (Updated June 25)

ID: 74132f91-e4d2-50d2-bb5e-247b996175a4

STIX ID: report--74132f91-e4d2-50d2-bb5e-247b996175a4

Feed Name: Palo Alto Networks Unit 42

Threat Score
85/100

Date Published: 2025-05-23

Date Updated: 2026-04-28

Author: Unit 42

...
...

Unit 42 describes CVE-2025-31324, an unauthenticated arbitrary-file-upload vulnerability in SAP NetWeaver Visual Composer that has been actively exploited in the wild to deploy JSP web shells, reverse shells (including a GOREVERSE ELF), reverse SSH SOCKS proxies, and Cobalt Strike beacons; the brief provides observed commands, network and file indicators (IPs, domains, SHA256 hashes), remediation recommendations, and product protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.