Critical SAP May 2025 Patch Fixes Zero-Day Exploit and 15 Security Flaws

Critical SAP May 2025 Patch Fixes Zero-Day Exploit and 15 Security Flaws

May 2025 SAP Security Bulletin: Zero-Day RCE Threat Amplifies, Cross-Industry Exploitation Confirmed

SAP’s May 2025 patch release takes center stage with an urgent security update that builds upon a high-priority emergency fix issued in April. At the heart of this release: a dangerous zero-day vulnerability (CVE-2025-31324) affecting SAP NetWeaver’s Visual Composer, now confirmed to be under active attack across a broad spectrum of global industries.

This month’s rollout includes 16 newly issued Security Notes and 2 updates to existing ones, with particular focus on neutralizing the RCE flaw in Visual Composer’s VCFRAMEWORK 7.50. Rated with a perfect CVSS 10.0, the vulnerability bypasses critical authentication controls, exposing unguarded endpoints to unauthenticated file uploads—effectively opening the door to full remote system takeover.

Behind the Breach: The Anatomy of CVE-2025-31324

First flagged by ReliaQuest on April 22 and quickly patched on April 24, the flaw stems from insufficient access validation within the Metadata Uploader component. This gap allows bad actors to upload and execute arbitrary files, including webshells like helper.jsp and cache.jsp, resulting in long-term backdoor access.

Follow-up research confirmed exploitation attempts as early as late January, with significant activity documented by February 10. What was initially suspected to be a simple file upload issue has evolved into verified remote command execution (RCE), as confirmed by Onapsis in their latest findings.

Widespread Impact Across Industries

This vulnerability’s reach is vast. Organizations in energy, manufacturing, government, oil and gas, retail, and pharma have all reported compromise. Despite not being enabled by default, SAP Visual Composer is active in an estimated 50–70% of Java-based deployments—dramatically increasing the attack surface.

Even more concerning, as of early May, security experts have observed a secondary wave of exploitation. Opportunistic attackers are now piggybacking on earlier breaches, reusing planted webshells to establish persistent access.

Recent campaigns have been linked to a threat group tracked as Chaya_004, with origins traced to China. These actors have demonstrated advanced capabilities in lateral movement and stealthy re-entry techniques.


Key Takeaway:
Organizations running SAP NetWeaver must prioritize immediate deployment of this patch—not only to stop the current threat but to prevent further exploitation by evolving adversaries already inside the perimeter.

If you’d like, I can also format this for use in a blog post, press release, or security advisory.

Vulnerability Overview

Risk ElementDescription
Impacted ComponentSAP NetWeaver – Visual Composer (VCFRAMEWORK version 7.50)
Threat PotentialEnables unauthenticated attackers to upload arbitrary files and execute remote code, leading to full system compromise
Attack RequirementsOnly network-level access to the vulnerable endpoint; no authentication needed
Severity Rating (CVSS)10.0 (Critical) – Full remote code execution risk without user interaction

Immediate Action Required: Defend SAP NetWeaver Systems from Active Exploitation

Organizations leveraging SAP NetWeaver must move swiftly to secure their environments in light of active, high-impact exploitation. This isn’t a routine update—it’s a frontline defense.

What You Need to Do Now

  • Deploy SAP Note #3594142 without delay. This updated patch addresses the core vulnerability being targeted in live attacks.
  • If patching must wait, activate mitigations as outlined in SAP Note #3593336 to reduce exposure until the update can be applied.
  • Initiate forensic reviews of potentially exposed systems to identify unauthorized access or indicators of compromise.

Why It’s Critical

This exploit grants attackers privileged <sid>adm access—the SAP OS-level superuser—putting your most sensitive systems in jeopardy. Real-world consequences include:

  • Unauthorized access to confidential or financial data
  • Manipulation of business-critical records
  • Ransomware payload deployment
  • Breaches of regulatory and compliance obligations

SAP’s Position

SAP continues to monitor threat activity closely, but the responsibility to act decisively lies with each organization. This patch must take precedence in your May 2025 security operations—delays may result in direct compromise.

More Articles & Posts