May 2025 SAP Security Bulletin: Zero-Day RCE Threat Amplifies, Cross-Industry Exploitation Confirmed
SAP’s May 2025 patch release takes center stage with an urgent security update that builds upon a high-priority emergency fix issued in April. At the heart of this release: a dangerous zero-day vulnerability (CVE-2025-31324) affecting SAP NetWeaver’s Visual Composer, now confirmed to be under active attack across a broad spectrum of global industries.
This month’s rollout includes 16 newly issued Security Notes and 2 updates to existing ones, with particular focus on neutralizing the RCE flaw in Visual Composer’s VCFRAMEWORK 7.50. Rated with a perfect CVSS 10.0, the vulnerability bypasses critical authentication controls, exposing unguarded endpoints to unauthenticated file uploads—effectively opening the door to full remote system takeover.
Behind the Breach: The Anatomy of CVE-2025-31324
First flagged by ReliaQuest on April 22 and quickly patched on April 24, the flaw stems from insufficient access validation within the Metadata Uploader component. This gap allows bad actors to upload and execute arbitrary files, including webshells like helper.jsp and cache.jsp, resulting in long-term backdoor access.
Follow-up research confirmed exploitation attempts as early as late January, with significant activity documented by February 10. What was initially suspected to be a simple file upload issue has evolved into verified remote command execution (RCE), as confirmed by Onapsis in their latest findings.
Widespread Impact Across Industries
This vulnerability’s reach is vast. Organizations in energy, manufacturing, government, oil and gas, retail, and pharma have all reported compromise. Despite not being enabled by default, SAP Visual Composer is active in an estimated 50–70% of Java-based deployments—dramatically increasing the attack surface.
Even more concerning, as of early May, security experts have observed a secondary wave of exploitation. Opportunistic attackers are now piggybacking on earlier breaches, reusing planted webshells to establish persistent access.
Recent campaigns have been linked to a threat group tracked as Chaya_004, with origins traced to China. These actors have demonstrated advanced capabilities in lateral movement and stealthy re-entry techniques.
Key Takeaway:
Organizations running SAP NetWeaver must prioritize immediate deployment of this patch—not only to stop the current threat but to prevent further exploitation by evolving adversaries already inside the perimeter.
If you’d like, I can also format this for use in a blog post, press release, or security advisory.
Vulnerability Overview
| Risk Element | Description |
|---|---|
| Impacted Component | SAP NetWeaver – Visual Composer (VCFRAMEWORK version 7.50) |
| Threat Potential | Enables unauthenticated attackers to upload arbitrary files and execute remote code, leading to full system compromise |
| Attack Requirements | Only network-level access to the vulnerable endpoint; no authentication needed |
| Severity Rating (CVSS) | 10.0 (Critical) – Full remote code execution risk without user interaction |
Immediate Action Required: Defend SAP NetWeaver Systems from Active Exploitation
Organizations leveraging SAP NetWeaver must move swiftly to secure their environments in light of active, high-impact exploitation. This isn’t a routine update—it’s a frontline defense.
What You Need to Do Now
- Deploy SAP Note #3594142 without delay. This updated patch addresses the core vulnerability being targeted in live attacks.
- If patching must wait, activate mitigations as outlined in SAP Note #3593336 to reduce exposure until the update can be applied.
- Initiate forensic reviews of potentially exposed systems to identify unauthorized access or indicators of compromise.
Why It’s Critical
This exploit grants attackers privileged <sid>adm access—the SAP OS-level superuser—putting your most sensitive systems in jeopardy. Real-world consequences include:
- Unauthorized access to confidential or financial data
- Manipulation of business-critical records
- Ransomware payload deployment
- Breaches of regulatory and compliance obligations
SAP’s Position
SAP continues to monitor threat activity closely, but the responsibility to act decisively lies with each organization. This patch must take precedence in your May 2025 security operations—delays may result in direct compromise.




