SAP patches recently utilized zero-day in the wake of Netweaver server attack


  • SAP FIXED CVE-2025-42999, a 9.1/10-vulnerability in Netweaver
  • This one was tied with CVE-2025-31324 which was attached in April
  • Fortune 500 -Companies are apparently in danger

SAP has patched a critical-difficulty zero-day vulnerability in Netweaver server, which was tied in attacks targeting some of the world’s largest companies.

Vulnerability is traced as CVE-2025-42999 and has a severity of 9.1/10 (critical). At NVD it was said that SAP Netweaver Visual Composer Metadata Uploader is “vulnerable when a privileged user can upload non -procedure or malicious content which, when deserialized, can potentially lead to a compromise of confidentiality, integrity and availability of the host system.”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top