CVE-2025-31324Active Exploitation(sap / netweaver)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch sap netweaver systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-05-20. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-434

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netweaver

Threat summary

  • Active exploitation appears in 10 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 19 mentions across 18 observed days

What's happening

  • Active exploitation reported across 10 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • General: 6 classified signals
  • Peaked 1d ago at 2 mentions (2026-09-08); latest day: 1
  • 19 total mentions across 18 days

Affected systems

Vendors
Products
netweaver

1 version affected across 1 product

Deep dive

Activity timeline19 mentions / 18d
01122Mentions · 2026-01-27: 1Mentions · 2026-01-29: 1Mentions · 2026-02-05: 1Mentions · 2026-02-09: 1Mentions · 2026-02-16: 1Mentions · 2026-02-26: 1Mentions · 2026-03-19: 1Mentions · 2026-04-01: 1Mentions · 2026-04-08: 1Mentions · 2026-04-14: 1Mentions · 2026-05-08: 1Mentions · 2026-05-18: 1Mentions · 2026-05-26: 1Mentions · 2026-06-09: 1Mentions · 2026-06-23: 1Mentions · 2026-06-24: 1Mentions · 2026-09-08: 2Mentions · 2026-09-23: 1PoC Mentioned / Linked · 2026-03-19: 1PoC Mentioned / Linked · 2026-09-08: 1Exploit Tool / Code · 2026-03-19: 1Exploit Tool / Code · 2026-09-08: 1Active Exploitation · 2026-01-27: 1Active Exploitation · 2026-02-09: 1Active Exploitation · 2026-02-16: 1Active Exploitation · 2026-02-26: 1Active Exploitation · 2026-03-19: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-04-14: 1Active Exploitation · 2026-05-08: 1Active Exploitation · 2026-05-26: 1Active Exploitation · 2026-06-24: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-14: 1Technical Details · 2026-05-18: 1Technical Details · 2026-05-26: 1Technical Details · 2026-06-24: 101-2701-2902-0502-0902-1602-2603-1904-0104-0804-1405-0805-1805-2606-0906-2306-2409-0809-23
Signal classification5 categories
Active Exploitation
1052.6%
General
631.6%
Patch
15.3%
Disclosure
15.3%
Exploit
15.3%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-01-271
Active Exploitation1
2026-01-291
General1
2026-02-051
General1
2026-02-091
Active Exploitation1
2026-02-161
Active Exploitation1
2026-02-261
Active Exploitation1
2026-03-191
Active Exploitation1
2026-04-011
Patch1
2026-04-081
Active Exploitation1
2026-04-141
Active Exploitation1
2026-05-081
Active Exploitation1
2026-05-181
Disclosure1
2026-05-261
Active Exploitation1
2026-06-091
General1
2026-06-231
General1
2026-06-241
Active Exploitation1
2026-09-082
Exploit1General1
2026-09-231
General1
Full discourse19 posts
  • X@SansLimit3
    Active Exploitation

    Exploitation infrastructure observed scanning for: CVE-2025-55182(React2shell) CVE-2026-21962(Oracle Weblogic) CVE-2025-31324(SAP NetWeaver) - actively exploited by China-linked APTs Targeting India-based critical infrastructure SAP exploit script "MADE BY SCATTERED LAPSUS$ HUNTERS" → likely tool reuse. Tooling includes fscan & Neo-reGeorg - commonly seen in China-linked intrusion tradecraft. C2s: 160[.]191.183.147:80 160[.]191.183.126:80 Seen on @Huntio ~ 1 month ago. @malwrhunterteam @polygonben @WhichbufferArda

    Post summary

    The post reports that CVE‑2025‑31324 in SAP NetWeaver is being actively exploited by China‑linked APTs, with specific exploitation scripts and tools such as fscan and Neo‑reGeorg observed scanning Indian critical infrastructure.

    27154244.6K
    231 followersView on X
  • Team Cymru Research@teamcymru_S2
    Active Exploitation

    🚨 Top 25 CVE Exploitation Attempts - Team Cymru - S2 (Ranked by unique source IPs over 14 days) 1. CVE-2025-0282 · Ivanti Connect Secure 2. CVE-2025-49706 · SharePoint 3. CVE-2020-3452 · Cisco ASA 4. CVE-2025-61884 · Oracle EBS 5. CVE-2024-32113 · Apache OFBiz 6. CVE-2025-53770 · SharePoint 7. CVE-2025-24893 · XWiki 8. CVE-2025-61882 · Oracle EBS 9. CVE-2025-5777 · Citrix NetScaler 10. CVE-2025-34028 · Commvault 11. CVE-2024-57727 · SimpleHelp 12. CVE-2025-20362 · Cisco ASA/FTD 13. CVE-2024-1212 · Kemp LoadMaster 14. CVE-2024-38856 · Apache OFBiz 15. CVE-2022-40684 · Fortinet 16. CVE-2024-9465 · Palo Alto Expedition 17. CVE-2025-11371 · Gladinet CentreStack 18. CVE-2025-58360 · GeoServer 19. CVE-2025-57819 · FreePBX 20. CVE-2025-31324 · SAP NetWeaver 21. CVE-2024-7593 · Ivanti vTM 22. CVE-2025-31125 · Vite Dev Server 23. CVE-2025-64446 · FortiWeb 24. CVE-2024-12987 · DrayTek Vigor 25. CVE-2018-7600 · Drupal

    Post summary

    The tweet enumerates the 25 CVEs with the highest observed exploitation attempts, indicating active exploitation, but it lacks technical details or mitigation information.

    070921.2K
    5.5K followersView on X
  • yousukezan@yousukezan
    General

    ET Openルールとハニーポットログを突合してみたら、SAP NetWeaver(CVE-2025-31324)関連の継続的スキャンが見えてきた https://qiita.com/shibacorgi/items/c12c508b73bd7bb875a5 #Qiita

    Post summary

    The author observes ongoing scanning activity targeting SAP NetWeaver CVE‑2025‑31324 by comparing ET Open rules with honeypot logs, but provides no proof of exploitation, PoC, or mitigation details.

    010211.2K
    14.8K followersView on X
  • Group-IB Global@GroupIB
    Active Exploitation

    Scattered Spider never touched a single production line controller. They exploited two SAP NetWeaver zero-days, CVE-2025-31324 and CVE-2025-42999, to breach Jaguar Land Rover's ERP environment. Assembly lines across four countries went dark. Five weeks. $250M in direct losses. A measurable dip in UK GDP. The attack did not start on the factory floor. It started in the enterprise IT layer. That gap, between where security programs focus and where attacks actually begin, is what is being exploited across European manufacturing right now. Group-IB recorded 228 ransomware DLS publications targeting European manufacturers in 2025. The UK, Germany, and Italy absorbed 57% of them. Qilin led by case volume (18%), followed by Akira (12%). ERP and SAP exploitation is now replacing phishing as the primary entry point. If your plant's IT and OT environments share a domain, that is the attack path. The full 2025 European manufacturing threat landscape, covering ransomware actors, IAB activity, OT access claims, and country profiles, is in the report. Full findings at Group-IB: https://link.group-ib.com/42ylj1w #Manufacturing #Ransomware #CyberSecurity

    Post summary

    Scattered Spider broke into JLR’s ERP via two SAP NetWeaver zero-days, shutting down plant lines across four countries and incurring $250M in losses, illustrating active exploitation of SAP vulnerabilities in European manufacturing.

    01020416
    9.6K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 استغلال ثغرة قديمة في strongSwan لتعطيل خدمات VPN عبر Integer Underflow تكشف الأبحاث عن ثغرة حرجة (CVE-2026-25075 و CVE-2025-31324) موجودة منذ 15 عامًا في إضافة EAP-TTLS ضمن برنامج strongSwan. تستغل هذه الثغرة خطأً حسابيًا من نوع "Integer Underflow" لإحداث فساد هائل في الذاكرة. يتيح هذا الاستغلال للمهاجمين تعطيل خدمات شبكات VPN (Virtual Private Networks) وإسقاطها، مما يؤدي إلى حرمان من الخدمة (Denial of Service). يُنصح بالتحديث الفوري لـ strongSwan لمعالجة هذه الثغرة وتجنب الانقطاعات المحتملة للخدمة. 🔗 للمزيد: https://hackread.com/strongswan-flaw-attackers-crash-vpn-integer-underflow/ #العربي_بلس #الامن_السيبراني #تقنية

    Post summary

    Researchers expose a long‑hidden integer underflow flaw in strongSwan’s EAP‑TTLS module that can crash VPN services; they urge users to update immediately to prevent potential denial‑of‑service attacks.

    0003044
    245 followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    CVE-2025-31324 = CVSS 10.0 (MAX severity), SAP NetWeaver unauthenticated RCE

    Post summary

    The text announces a high‑severity vulnerability (CVSS 10.0) in SAP NetWeaver that allows unauthenticated remote code execution, but does not provide exploit details or remediation advice.

    1001054
    1.3K followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-GH-kQoXBqt [CRITICAL/PoC] Linked: CVE-2025-31324 CVE-2025-31324 🔗 https://exploitgrid.net/exploits/5ba22d0f-2adb-4d37-986f-3f3946bc1b8b

    Post summary

    A publicly available PoC/exploit for CVE-2025-31324 is shared on Exploit-Grid, but there is no evidence of active exploitation or remediation advice.

    1000041
    41 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2024-3094 CVE-2025-31324 CVE-2025-55182 CVE-2025-57819 CVE-2026-28576 ..🧵👇

    Post summary

    The message simply enumerates several newly disclosed CVEs without offering details on exploitation, patches, or technical specifics.

    1000051
    41 followersView on X
  • Silent Vector@gh0st_V3ctbrv
    Active Exploitation

    Qilin's initial access playbook 👇 → phishing + spear phishing — AI-generated lures, near-impossible to spot → VPN exploitation — FortiGate CVE-2024-55591, CVE-2024-21762 → SAP NetWeaver zero-day — CVE-2025-31324 (CVSS 10.0) exploited before public disclosure → Check Point VPN — CVE-2026-50751 actively exploited this month → MSP supply chain — compromise one IT provider → push ransomware to all their clients one MSP breach in South Korea let them hit 25 financial firms in a single month. 🏦

    Post summary

    The post notes several CVEs being leveraged, including an actively exploited Check Point VPN flaw and a zero-day used prior to disclosure, but no PoC or patch information is supplied.

    10000116
    9.3K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    Microsoft の警告:N-Day 脆弱性を悪用する Storm-1175 がMedusa を高速展開 https://iototsecnews.jp/2026/04/07/microsoft-warns-storm-1175-exploiting-web-facing-vulnerabilities-to-deploy-medusa-ransomware/ 金銭的な動機を持つ Storm-1175 が、修正プログラムが公開された直後の N-day 脆弱性を武器化していると、Microsoft が警告しています。事例としては、SAP NetWeaver の CVE-2025-31324 が、アドバイザリ公開からわずか 1 日後に悪用が開始されたケースが確認されています。攻撃者はインターネットに公開されたインフラの隙を突き、管理ツールを悪用して数日以内にランサムウェアを展開します。したがって、公開システムへのパッチ適用の遅れや境界防御の不備が、直接的な侵入の引き金となります。脆弱性情報の公開直後から狙われるリスクを想定し、迅速な更新管理や資産の可視化を徹底することが、被害を防ぐための重要な鍵となります。 #CVE202531324 #Microsoft #NDay #Vulnerability

    Post summary

    Microsoft warns that the threat actor Storm‑1175 is actively exploiting newly disclosed vulnerabilities—most notably CVE‑2025‑31324—to rapidly deploy Medusa ransomware, emphasizing urgent patching and perimeter hardening.

    01000231
    484 followersView on X
  • Cyber News Live@cybernewslive
    Active Exploitation

    A new report reveals that attackers focus on a tiny fraction of security flaws, exploiting just 1% of discovered vulnerabilities. These targeted flaws — React2Shell (CVE-2025-55182), Microsoft SharePoint (CVE-2025-53770), and SAP NetWeaver (CVE-2025-31324) — are exploited rapidly, often before patches are available. China-linked groups and ransomware gangs like Cl0p remain highly active, increasing their exploitation speed and scale. 💀 #CyberNewsLive https://hackread.com/1-security-flaws-drive-cyberattacks-2025-report/

    Post summary

    The report indicates that a small subset of vulnerabilities, including CVE‑2025‑55182, CVE‑2025‑53770, and CVE‑2025‑31324, are being actively exploited by threat actors before patches are released.

    0001087
    1.5K followersView on X
  • Layer Seven Security@LayerSeven
    General

    SAP Zero Day Vulnerability CVE-2025-31324 / Security Note 3594142 https://layersevensecurity.com/sap-zero-day-vulnerability-cve-2025-31324-security-note-3594142 https://t.co/Ww8PKI6WeQ

    Post summary

    The text announces a SAP zero-day vulnerability with CVE-2025-31324 and references security note 3594142, but lacks details on PoC, exploits, active exploitation, patches, or technical specifics.

    0000066
    391 followersView on X
  • Edy Werder@edy_werder
    General

    I ran Fail2ban and CrowdSec side by side on identical VMs for 2 days. Same hardware, same attacks. CrowdSec caught CVE-2025-31324 automatically. Fail2ban missed every CVE pattern, but it took only 5 minutes to set up. https://edywerder.ch/fail2ban-vs-crowdsec/ #Homelab #CrowdSec #Fail2ban

    Post summary

    The post compares Fail2ban and CrowdSec, noting that CrowdSec automatically detected CVE‑2025‑31324, but offers no proof‑of‑concept, exploit details, patch information, or technical specifics.

    0000026
    325 followersView on X
  • @pedri77@pedri77
    Active Exploitation

    At least two different cybercrime groups BianLian and RansomExx are said to have exploited a recently disclosed security flaw in SAP NetWeaver tracked as CVE-2025-31324, indicating that multiple threat actors are taking... https://f.mtr.cool/ikyskhgkob

    Post summary

    Two cybercrime groups, BianLian and RansomExx, are reported to have exploited CVE‑2025‑31324 in SAP NetWeaver, indicating active malicious use of the flaw.

    00000965
    2.1K followersView on X
  • @pedri77@pedri77
    Active Exploitation

    Threat actors launch second wave of attacks on SAP NetWeaver, exploiting webshells from a recent zero-day vulnerability. In April, ReliaQuest researchers warned that a zero-day vulnerability, tracked as CVE-2025-31324 (... https://f.mtr.cool/yevnxzmujq

    Post summary

    Threat actors are actively exploiting the CVE-2025-31324 zero‑day via webshells in a second wave of attacks against SAP NetWeaver.

    0000034
    2.1K followersView on X
  • Layer Seven Security@LayerSeven
    Active Exploitation

    SAP Vulnerability Actively Exploited by Ransomware Groups and Threat Actors https://layersevensecurity.com/sap-vulnerability-actively-exploited-cve-2025-31324 https://t.co/TEn7HCDQjb

    Post summary

    The tweet claims that SAP vulnerability CVE-2025-31324 is being actively exploited by ransomware groups, but offers no evidence, technical details, or remediation information.

    0000082
    390 followersView on X
  • Layer Seven Security@LayerSeven
    General

    SAP Zero Day Vulnerability CVE-2025-31324 / Security Note 3594142 https://layersevensecurity.com/sap-zero-day-vulnerability-cve-2025-31324-security-note-3594142 https://t.co/ffGE7KEGap

    Post summary

    The tweet links to a source discussing SAP CVE‑2025‑31324, but offers no additional details or evidence of exploitation.

    0000082
    390 followersView on X
  • Onapsis@onapsis
    General

    Collaboration is what determines if a zero-day is catastrophic or contained. 🔒 In one week, we’ll provide a behind-the-scenes look at our coordinated response around CVE-2025-31324 with SAP. 🗓️ Feb 5 | 10am EST 🔗 https://bit.ly/49ob6HI https://t.co/29byyfc5JR

    Post summary

    The tweet announces an upcoming behind‑the‑scenes look at the coordinated response to CVE‑2025‑31324 with SAP, but does not provide any technical, exploitation, patch, or PoC details.

    00000120
    4.5K followersView on X
  • @pedri77@pedri77
    Active Exploitation

    At least two different cybercrime groups BianLian and RansomExx are said to have exploited a recently disclosed security flaw in SAP NetWeaver tracked as CVE-2025-31324, indicating that multiple threat actors are taking... https://f.mtr.cool/yamyavynop

    Post summary

    The post reports that multiple threat actors are actively exploiting the newly disclosed SAP NetWeaver vulnerability CVE‑2025‑31324.

    0000063
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsapnetweaver7.50--

Explore more