SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. This file when executed can lead to a full compromise of confidentiality, integrity and availability of the system.
https://www.theregister.com/2025/09/10/microsoft_patch_tuesday/
https://www.securityweek.com/sap-patches-critical-netweaver-vulnerabilities/
https://thehackernews.com/2025/09/sap-patches-critical-netweaver-cvss-up.html
https://securityaffairs.com/182040/security/sap-september-2025-patch-day-fixed-4-critical-flaws.html