SAP NetWeaver Under Siege: Critical Zero-Day Vulnerability Exploited in the Wild

Listen to this Post

Featured Image

Introduction

In a stark reminder of the cybersecurity threats lurking in enterprise software, a newly discovered zero-day vulnerability in SAP NetWeaver has sparked widespread concern across the global tech landscape. Identified as CVE-2025-31324, this flaw carries the highest possible CVSS severity score of 10, meaning it’s as critical as vulnerabilities come. What’s most alarming? It’s already being actively exploited in the wild — affecting thousands of systems that form the digital backbone of major industries and government institutions.

This vulnerability, linked specifically to the SAP Visual Composer component, allows unauthenticated attackers to upload files directly into targeted systems. With this access, they can deploy web shells and achieve full remote code execution — effectively taking control of entire systems. Despite an emergency patch issued by SAP, many systems remain vulnerable, and the scope of the compromise is still unfolding.

SAP NetWeaver Vulnerability: What You Need to Know

  • A newly disclosed vulnerability — CVE-2025-31324 — is currently being widely exploited across the internet.
  • The flaw allows unauthorized file uploads, giving attackers remote code execution capabilities on affected SAP NetWeaver systems.
  • It specifically targets the SAP Visual Composer, a powerful modeling tool commonly enabled in enterprise environments.
  • The vulnerability holds a CVSS score of 10, indicating maximum severity.
  • watchTowr and other cybersecurity firms confirm active exploitation in the wild, with attackers deploying web shell backdoors.
  • These backdoors offer remote access, likely being resold to ransomware gangs and other threat actors.
  • ReliaQuest disclosed the vulnerability publicly, while SAP followed up with an emergency patch.
  • Unfortunately, SAP’s advisory is only accessible to paying customers, limiting public awareness.
  • JP Perez-Etchegousd of Onapsis estimates 50-70% of internet-facing SAP NetWeaver Java instances are potentially exposed.
  • Internet search tools like Shodan and Censys reveal around 10,000 SAP systems might be vulnerable.
  • SAP Visual Composer isn’t always installed by default, but it’s widely enabled due to its role in business process modeling.
  • Attackers are believed to be part of a sophisticated group — possibly initial access brokers — who may have sold access to other cybercriminals.
  • The deployed backdoors reportedly lack access controls, creating an opportunity for any threat actor to exploit them.
  • These weaknesses could fuel a new wave of ransomware attacks, as cybercriminals now have clear blueprints to exploit vulnerable systems.
  • Government agencies and global enterprises using SAP are particularly at risk due to the platform’s central role in business operations.
  • Security experts warn this situation is “as bad as it can get” — an unauthenticated remote attack through HTTP that allows total system takeover.
  • Multiple incident response teams are currently engaged in analyzing the extent of damage across compromised organizations.
  • Analysts stress that most of the exploitation likely occurred before the vulnerability was publicly disclosed.
  • The identity of the attackers is still unknown, though their tactics strongly suggest they’re professionals with high-level capabilities.
  • SAP’s slow public response and the paywall for security advisories raise questions about transparency in enterprise security.
  • System administrators are being urged to apply SAP’s emergency patch immediately and audit systems for signs of compromise.
  • With over 400,000 SAP customers worldwide, the scale of the threat is immense and still expanding.
  • The exploit allows threat actors to bypass login credentials, compromising systems without triggering standard security defenses.
  • Once inside, attackers gain administrator-level privileges, enabling them to exfiltrate data, halt operations, or launch deeper attacks.
  • There’s no current estimate for how many systems have already been compromised.
  • Analysts expect the number of attacks to rise dramatically, especially as knowledge of the exploit spreads.
  • Ransomware deployment is seen as the next logical step in the exploitation chain.
  • The security community is racing to contain the damage and understand how long the vulnerability has been exploited prior to discovery.
  • Threat researchers emphasize that time is critical — organizations that delay patching could face catastrophic consequences.

What Undercode Say:

The CVE-2025-31324 vulnerability impacting SAP NetWeaver isn’t just another routine security patch; it’s a red alert for any enterprise using SAP infrastructure. What makes this flaw especially terrifying is not only its technical ease of exploitation but also the widespread deployment of the affected component, SAP Visual Composer. Despite not being installed by default, it remains prevalent across thousands of organizations because of its utility in non-developer business applications.

From an

Initial access brokers — a critical link in today’s cybercrime ecosystem — appear to be the driving force behind the attacks. Their role is to penetrate systems and sell that access to ransomware operators, data brokers, or nation-state actors. But this time, their operational security may have faltered. The backdoors they deployed were not access-restricted, meaning any knowledgeable attacker can now piggyback off the exploitation path already carved.

This blunder could trigger a ransomware gold rush as various cybercriminal factions rush to weaponize the vulnerability for their own ends. The result? A massive spike in attacks targeting SAP systems — especially those exposed to the public internet. And with an estimated 10,000 such instances online, the field is ripe for plundering.

The lack of a public-facing security alert from SAP further complicates matters. Many IT teams may not even be aware of the urgency, especially if they aren’t subscribed to SAP’s internal advisories. This lack of transparency could delay crucial patching efforts and extend the exploitation window further.

Another disturbing element is the possibility that exploitation began well before public disclosure. If this is the case, many companies may have been compromised for weeks or even months without knowing it. Indicators of compromise could be subtle, buried in server logs or masked under routine traffic — making detection a challenge.

In light of these developments, organizations should:

– Immediately patch SAP systems.

  • Perform a forensic review of recent file uploads and web directories.
  • Restrict internet exposure of SAP NetWeaver Java instances.

– Deploy anomaly detection and endpoint monitoring tools.

  • Consider engaging with cybersecurity firms for deeper threat hunting.

The story of CVE-2025-31324 is still unfolding, but one thing is clear: it’s a wake-up call. Enterprise platforms like SAP are high-value targets and must be treated as such. Reactive patching is no longer sufficient — proactive security architecture, continuous monitoring, and incident readiness are the new non-negotiables in enterprise cyber hygiene.

Fact Checker Results:

  • CVE-2025-31324 is confirmed and carries a CVSS score of 10, indicating a critical risk.
  • Multiple cybersecurity firms have verified real-world exploitation, including web shell deployment.
  • SAP issued an emergency patch, but full advisory details remain gated behind customer credentials.

References:

Reported By: cyberscoop.com
Extra Source Hub:
https://stackoverflow.com
Wikipedia
Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 Telegram