Attackers are actively exploiting critical SAP NetWeaver Visual Composer vulnerability CVE-2025-31324 in the Metadata Uploader component. Insufficient access controls allow unauthenticated remote attackers to upload malicious files to vulnerable servers, with observed intrusions deploying webshells to establish persistent access.
SAP issued an emergency patch, while the Dutch National Cyber Security Centre assessed the threat at High/High and warned that webshells linked to the exploit are being sold online, increasing the risk of widespread abuse. Organizations should immediately apply SAP’s fixes, identify internet-exposed NetWeaver instances, and investigate affected systems for uploaded webshells and other indicators of compromise.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
SAP released an emergency patch for CVE-2025-31324 and security updates for other affected SAP products. The NCSC raised the associated threat level to High/High and advised organizations to promptly patch and inspect exposed systems for webshells.
Attackers exploiting CVE-2025-31324 deployed webshells on compromised systems, enabling later persistent access. Webshells associated with this exploitation were reportedly offered for sale online.
SAP and the Dutch NCSC observed active exploitation of CVE-2025-31324, a critical insufficient-access-control flaw in the Metadata Uploader component of SAP NetWeaver Visual Composer. The flaw allows unauthenticated attackers to upload malicious files to vulnerable servers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.