A new exploit that combines two critical (now patched) vulnerabilities in SAP NetWeaver has emerged, putting organizations and users at risk.

The exploit combines CVE-2025-31324 and CVE-2025-42999 to bypass authentication and achieve remote code execution, according to security firm Onapsis.
CVE-2025-31324 (CVSS score: 10.0) is related to the absence of authentication in the SAP NetWeaver Visual Composer development server, while CVE-2025-42999 (CVSS score: 9.1) is related to insecure Deserialization on the same server.
See also: CISA: Warns of vulnerability in Trend Micro Apex One
SAP NetWeaver: Vulnerability Fix
These vulnerabilities were patched by SAP in April and May 2025, but not before they were used by malicious actors as zero-days. The first attacks were recorded in March. Several ransomware and extortion groups, including Qilin, BianLian, and RansomExx , have been observed exploiting these vulnerabilities, along with several China-linked espionage groups targeting critical infrastructure networks
The existence of the exploit was first reported by vx-underground, who noted that it was released by the Scattered Lapsus$ Hunters, a new alliance formed by Scattered Spider and ShinyHunters.
Onapsis, for its part, stated: “These vulnerabilities allow an unauthorized attacker to execute arbitrary commands on the target SAP System, including uploading arbitrary files. This can lead to remote code execution (RCE) and complete compromise of the affected system and SAP business data and processes.”
See also: Intel vulnerabilities allowed employee data breach

The exploit can be used to deploy web shells, as well as perform living-off-the-land (LotL) attacks by executing operating system commands without leaving any additional files on the compromised system. These commands are executed with SAP administrator privileges , providing unauthorized access to SAP system data and resources.
The attack chain first uses the CVE-2025-31324 vulnerability to bypass authentication and upload the malicious payload to the server. The Deserialization vulnerability (CVE-2025-42999) is then used to decompress the payload and execute it with elevated privileges.
Onapsis warned that the publication of this deserialization gadget is concerning because it can be reused in other contexts, such as exploiting deserialization vulnerabilities patched by SAP in July [(CVE-2025-30012 (CVSS score: 10.0), CVE-2025-42963 (CVSS score: 9.1), CVE-2025-42964 (CVSS score: 9.1), CVE-2025-42966 (CVSS score: 9.1), CVE-2025-42980 (CVSS score: 9.1)].
See also: PyPI: Malicious packages exploit dependency for supply chain attacks
Describing the malicious actors as having extensive knowledge of SAP applications, Onapsis urges SAP users to apply the latest patches as soon as possible, review and restrict access to SAP applications from the internet, and monitor SAP applications for any signs of compromise.

The new SAP NetWeaver exploit once again highlights how attractive high-value enterprise systems for malicious actors. The fact that the exploit combines two critical vulnerabilities (CVE-2025-31324 and CVE-2025-42999) to achieve authentication bypass and remote code executionmakes the threat extremely dangerous.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Critical PostgreSQL vulnerabilities allow Code Injection
Furthermore, the incident highlights the classic problem of patch management in large enterprise systems: even if patches are made available by the vendor, many systems remain exposed due to delays in applying updates or due to operational limitations (e.g. downtime in critical environments).
SAP NetWeaver is a cornerstonefor critical business functions (ERP, finance, procurement, HR). A breach is not just a technical loss, but can affect supply chains, financial transactions and confidential data. The involvement of ransomware groups (Qilin, BianLian, RansomExx) and state-sponsored APTs shows that the threat is twofold: financial extortion and espionage of critical infrastructure.
