SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html
https://hackread.com/storm-1175-hackers-24-hour-medusa-ransomware-flaw/
https://thehackernews.com/2026/04/china-linked-ta416-targets-european.html
https://cyberscoop.com/social-engineering-surge-intrusion-vector-mandiant-m-trends/
https://cloud.google.com/blog/topics/threat-intelligence/ransomware-ttps-shifting-threat-landscape/
https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates
https://thehackernews.com/2025/12/chinese-hackers-have-started-exploiting.html
https://www.darkreading.com/vulnerabilities-threats/sap-4hana-vulnerability-under-attack
https://securelist.com/malware-report-q2-2025-pc-iot-statistics/117421/
https://securelist.com/vulnerabilities-and-exploits-in-q2-2025/117333/
https://www.darkreading.com/cyberattacks-data-breaches/critical-sap-vulns-under-exploitation
https://www.securityweek.com/new-exploit-poses-threat-to-sap-netweaver-instances/
https://thehackernews.com/2025/08/public-exploit-for-chained-sap-flaws.html
https://thehackernews.com/2025/07/hackers-exploit-sap-vulnerability-to.html
https://www.infosecurity-magazine.com/news/auto-color-backdoor-exploits-sap/
https://hackread.com/sap-netweaver-vulnerability-auto-color-malware-us-firm/
https://www.darkreading.com/threat-intelligence/earth-lamia-exploits-sql-rce-bugs-asia
https://thehackernews.com/2025/05/china-linked-hackers-exploit-sap-and.html
https://www.securityweek.com/chinese-hacking-group-earth-lamia-targets-multiple-industries/
https://www.trendmicro.com/en_us/research/25/e/earth-lamia.html
https://thehackernews.com/2025/05/chinese-hackers-exploit-ivanti-epmm.html
https://www.securityweek.com/ransomware-groups-chinese-apts-exploit-recent-sap-netweaver-flaws/
https://www.infosecurity-magazine.com/news/microsoft-seven-zerodays-may-patch/
https://www.bleepingcomputer.com/news/security/ransomware-gangs-join-ongoing-sap-netweaver-attacks/
https://thehackernews.com/2025/05/bianlian-and-ransomexx-exploit-sap.html
https://www.securityweek.com/sap-patches-another-critical-netweaver-vulnerability/
https://www.securityweek.com/sap-zero-day-targeted-since-january-many-sectors-impacted/
https://unit42.paloaltonetworks.com/threat-brief-sap-netweaver-cve-2025-31324/
https://thehackernews.com/2025/05/chinese-hackers-exploit-sap-rce-flaw.html
https://www.securityweek.com/second-wave-of-attacks-hitting-sap-netweaver-after-zero-day-compromise/
https://redcanary.com/blog/threat-intelligence/cve-2025-31324/
https://www.helpnetsecurity.com/2025/04/28/sap-netweaver-cve-2025-31324-exploited/
https://hackread.com/sap-netweaver-flaw-severity-hackers-deploy-web-shells/
https://www.theregister.com/2025/04/25/sap_netweaver_patch/
https://www.securityweek.com/sap-zero-day-possibly-exploited-by-initial-access-broker/
https://thehackernews.com/2025/04/sap-confirms-critical-netweaver-flaw.html
https://cyberscoop.com/sap-netweaver-zero-day-exploit-cve-2025-31324/
https://github.com/aristois913/CVE-2025-31324
https://github.com/R4ptX/DeepDives
https://github.com/PuddinCat/GithubRepoSpider
https://github.com/nairuzabulhul/nuclei-template-cve-2025-31324-check
https://github.com/Onapsis/Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment
https://github.com/JonathanStross/CVE-2025-31324
https://github.com/respondiq/jsp-webshell-scanner
https://github.com/BlueOWL-overlord/Burp_CVE-2025-31324
https://github.com/Pengrey/CVE-2025-31324
https://github.com/cybersecplayground/PoC-and-CVE-Reports
https://github.com/moften/CVE-2025-31324-NUCLEI
https://github.com/Totunm/CVE-2025-31324
https://github.com/Onapsis/Onapsis_CVE-2025-31324_Scanner_Tools
https://github.com/redrays-io/CVE-2025-31324
https://github.com/mananjain61/ExploitCVE2025
https://github.com/Profanatic/ExploitCVE2025
https://github.com/rxerium/CVE-2025-31324
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31324
Published: 2025-04-24
Updated: 2026-08-04
Known Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.99512
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest