SAP patched CVE-2025-31324, a critical CVSS 10.0 flaw in SAP NetWeaver Visual Composer that lets unauthenticated attackers send crafted HTTP POST requests to /developmentserver/metadatauploader, upload arbitrary files, and achieve remote code execution. Security researchers and national CSIRT reporting said the bug was actively exploited against exposed, high-value SAP systems, with attackers planting JSP webshells for persistent remote access and using the compromise to fully take over affected servers. SAP addressed the issue in Security Note 3594142 and urged customers to patch immediately or temporarily reduce exposure by disabling Visual Composer, disabling the developmentserver alias, and restricting access to the vulnerable endpoint.
A second NetWeaver Visual Composer flaw, CVE-2025-42999, was later fixed in Security Note 3604119 after reports that attackers were chaining it with the first bug for stealthier post-compromise activity. That deserialization vulnerability requires high privileges but can also lead to arbitrary file upload and code execution, and researchers said exploitation had been observed since at least January 2025. Reporting linked the campaign to multiple threat actors, including BianLian and RansomEXX, with intrusions involving tools such as Brute Ratel and Heaven's Gate techniques to evade detection, prompting defenders to review uploaded files, inspect logs, and hunt for unauthorized webshells and follow-on payloads.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
SAP released security updates to fix CVE-2025-42999, a critical insecure deserialization vulnerability in SAP NetWeaver Visual Composer that can allow remote code execution and full system compromise. Defenders were advised to urgently apply SAP Security Note 3604119 and consider mitigations such as disabling Visual Composer or restricting access to the vulnerable endpoint.
Onapsis researchers said CVE-2025-42999, an insecure deserialization flaw in SAP NetWeaver Visual Composer, has been actively exploited since at least January 2025. The exploitation was linked to attacks involving CVE-2025-31324.
Reporting described attackers exploiting CVE-2025-31324 to upload JSP webshells to SAP NetWeaver systems, gain remote control, and deploy follow-on tooling such as Brute Ratel while using Heaven's Gate techniques for evasion. The activity was attributed to multiple threat actors, including BianLian and RansomEXX, and affected high-value enterprise and government SAP environments.
SAP released a patch for the critical SAP NetWeaver Visual Composer vulnerability CVE-2025-31324. Multiple sources described the flaw as actively exploited in the wild and urged customers to apply SAP Security Note 3594142 immediately.
ReliaQuest uncovered CVE-2025-31324 in SAP NetWeaver Visual Composer, a critical unauthenticated file-upload vulnerability that enables remote code execution. The company notified SAP and developed detection mechanisms for customers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcecsirt.sk
Open sourceredrays.io
Open sourcereliaquest.com
Open sourceme.sap.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.