SAP’s Security Patch Day: NetWeaver’s Wild Exploits and the Race to Patch

SAP’s May 2025 Security Patch Day dropped 16 new and two updated security notes, tackling critical vulnerabilities in NetWeaver. The most severe bug, CVE-2025-31324, scores a perfect 10/10 on the CVSS scale and has been exploited since January. SAP users, patch up quickly or risk playing unwitting host to opportunistic webshells!

Pro Dashboard

Hot Take:

SAP’s May 2025 Security Patch Day is like Christmas for cybersecurity folks, except instead of gifts under the tree, you get a dozen security notes. This time, SAP is putting out fires with two critical vulnerabilities in NetWeaver. Because nothing says ‘Happy Patch Day’ like a CVE score of 10/10!

Key Points:

  • SAP released 16 new and two updated security notes during the May 2025 Security Patch Day.
  • The most severe vulnerability, CVE-2025-31324, is already being exploited in the wild for remote code execution.
  • Another critical vulnerability, CVE-2025-42999, involves insecure deserialization in NetWeaver’s Visual Composer.
  • Additional critical updates address code injection issues in S/4HANA and Landscape Transformation.
  • SAP customers are urged to apply these patches immediately to fend off exploitation.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?