top of page

CYBER & INFOSEC

"blogger, InfoSec specialist, super hero ... and all round good guy" 

DISCUSSIONS, CONCEPTS & TECHNOLOGIES FOR THE WORLD OF

JOIN THE DISCUSSION

SAP NetWeaver Critical RCE Vulnerability Under Mass Exploitation — Patch or Take Offline Now

  • May 19
  • 2 min read

A critical remote code execution vulnerability in SAP NetWeaver is being actively mass-exploited across hundreds of internet-exposed systems, according to researchers at ReliaQuest and Mandiant. The flaw, tracked as CVE-2025-42999 with a CVSS score of 9.8, allows unauthenticated attackers to upload and execute arbitrary files through SAP's Visual Composer development server component. This is a maximum-severity vulnerability with a trivial exploitation path.

SAP NetWeaver is the integration and application platform underlying many enterprise-critical SAP systems including ERP, supply chain management, and financial applications. It is widely deployed across Fortune 500 companies, government agencies, defense contractors, and healthcare systems globally. The Visual Composer component affected by this vulnerability is enabled by default in many installations and is frequently exposed to the internet for developer access.

In the wild, attackers are uploading JSP web shells to compromised SAP servers, establishing persistent backdoor access. Researchers observed multiple threat actors operating simultaneously on the same compromised hosts, suggesting initial access brokers are selling footholds as fast as they can establish them. Some compromised servers showed evidence of three separate threat actors with overlapping access, each pursuing different objectives ranging from data theft to ransomware staging. CISA added CVE-2025-42999 to the Known Exploited Vulnerabilities catalog, mandating federal agency patching within 48 hours.

Every organization running SAP NetWeaver with Visual Composer enabled and internet-exposed is at immediate risk. This spans manufacturing, energy, financial services, logistics, and government sectors where SAP is the backbone of business operations.

Immediate actions: disable or firewall the SAP Visual Composer component if not in active use, apply SAP Security Note 3594142 immediately, scan all SAP NetWeaver systems for existing web shells using SAP's provided indicators of compromise, and review all recent file uploads and configuration changes in the Visual Composer path. If exploitation is suspected, isolate the affected system and engage incident response before patching, as patching an actively compromised system without full forensic review may destroy evidence.

Mass exploitation of SAP NetWeaver represents attackers going directly after business-critical infrastructure — the systems that run payroll, manage supply chains, and control financial operations for the world's largest organizations.

Source: https://www.bleepingcomputer.com/news/security/sap-netweaver-servers-hacked-in-ongoing-attacks/

1 Comment


fuxohe
a day ago

Such coordination implies a history of working together on previous successful hits. The focus on the back office https://youtu.be/QPrnUUEnmEc?si=EH8hbwaBRklWoQeN area suggests they have specific intelligence about where the largest sums of cash are held.

Like

doctorchaos.com and drchaos.com is a blog dedicated to Cyber Counter Intelligence and Cybersecurity technologies. The posts will be a discussion of concepts and technologies that make up emerging threats and techniques related to Cyber Defense. Sometimes we get a little off-topic. Articles are gathered or written by cyber security professionals, leading OEMs, and enthusiasts from all over the world to bring an in-depth, real-world, look at Cyber Security. About this blog doctorchaos.com and drchaos.com and any affiliate website does not represent or endorse the accuracy or reliability of any information’s, content or advertisements contained on, distributed through, or linked, downloaded or accessed from any of the services contained on this website, nor the quality of any products, information’s or any other material displayed, purchased, or obtained by you as a result of an advertisement or any other information’s or offer in or in connection with the services herein. Everything on this blog is based on personal opinion and should be interoperated as such. Contact Info If you would like to contact this blog, you may do so by emailing ALAKHANI(AT)YMAIL(DOT)COM  

SOCIALS 

SUBSCRIBE 

Keeping you informed | Latest News

© 2018 Dr. Chaos 

bottom of page