CVE detail
CVE-2025-31324
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
33 source links · newest first
- Attackers are handing off access in 22 seconds, Mandiant findsHelp Net Security
Exploits remain the leading entry point for attackers for the sixth consecutive year, according to Mandiant’s M-Trends 2026 report, which draws on more than 500,000 hours of incident response work conducted in 2025. The data shows attackers speeding up their internal hand-offs, shifting away from email phishing, and targeting backup and virtualization infrastructure with greater precision. Initial infection vector 2025 (Source: Mandiant) Voice phishing surges as email phishing continues to decline Voice phishing climbed to … More →
newswww.helpnetsecurity.comMar 24, 2026, 6:00 AM The latest M-Trends report is based on insights from over 500,000 hours of Mandiant incident response investigations in 2025.
newswww.securityweek.comMar 23, 2026, 3:00 PM- Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat LandscapeMandiant
loits were used or suspected, the threat actors targeted vulnerabilities in common VPNs and firewalls such as Fortinet (CVE-2024-55591, CVE-2024-21762, and CVE-2019-6693), SonicWall (CVE-2024-40766), Palo Alto (CVE-2024-3400), and Citrix (CVE-2023-4966). We also observed malicious actors successfully exploit a variety of other exposed services, includi
vendorcloud.google.comMar 16, 2026, 2:00 PM On September 2025 Patch Tuesday, Microsoft has released patches for 80+ vulnerabilities in its various software products, but the good news is that none of them are actively exploited. Among the critical and important vulnerabilities patched by Microsoft this time around are: CVE-2025-54918, a remotely exploitable Windows NTLM elevation of privilege vulnerability. “The attack complexity is Low because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with … More →
newswww.helpnetsecurity.comSep 10, 2025, 10:52 AM- Week in review: Covertly connected and insecure Android VPN apps, Apple fixes exploited zero-dayHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Android VPN apps used by millions are covertly connected AND insecure Three families of Android VPN apps, with a combined 700 million-plus Google Play downloads, are secretly linked, according to a group of researchers from Arizona State University and Citizen Lab. Apple fixes zero-day vulnerability exploited in “extremely sophisticated attack” (CVE-2025-43300) Apple has fixed yet another vulnerability (CVE-2025-43300) that has … More →
newswww.helpnetsecurity.comAug 24, 2025, 8:00 AM A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Kidney dialysis firm DaVita confirms ransomware attack compromised data of 2.7M people China-linked Silk Typhoon APT […]
newssecurityaffairs.comAug 24, 2025, 7:17 AMA working exploit concatenating two critical SAP Netweaver vulnerabilities (CVE-2025-31324, CVE-2025-42999) that have been previously exploited in the wild has been made public by VX Underground, Onapsis security researchers have warned. The exploit has allegedly been released on a Telegram channel that claimed to represent a collective of three established cybercrime groups: Scattered Spider, ShinyHunters, and LAPSUS$. Historical exploitation of CVE-2025-31324 Earlier this year, a suspected initial access broker group abused CVE-2025-31324 – a missing … More →
newswww.helpnetsecurity.comAug 20, 2025, 10:28 AM- Exploit weaponizes SAP NetWeaver bugs for full system compromiseSecurity Affairs
Exploit chaining CVE-2025-31324 & CVE-2025-42999 in SAP NetWeaver enables auth bypass and RCE, risking compromise and data theft. A new exploit chaining two vulnerabilities, tracked as CVE-2025-31324 and CVE-2025-42999, in SAP NetWeaver exposes organizations to the risk of system compromise and data theft. CVE-2025-31324 (CVSS score: 10.0) is a missing authorization check in NetWeaver’s Visual Composer […]
newssecurityaffairs.comAug 20, 2025, 12:01 AM A new public exploit chains two critical flaws in SAP NetWeaver, exposing unpatched instances to code execution attacks.
newswww.securityweek.comAug 19, 2025, 10:04 AMHackers exploited a SAP NetWeaver bug to deploy upgraded Auto-Color Linux malware in an attack on U.S. chemicals firm. Cybersecurity firm Darktrace reported that threat actors exploited a SAP NetWeaver flaw, tracked as CVE-2025-31324, to deploy Auto-Color Linux malware in a U.S. chemicals firm attack. “In April 2025, Darktrace identified an Auto-Color backdoor malware attack […]
newssecurityaffairs.comJul 30, 2025, 7:46 AMThreat actors recently tried to exploit a freshly patched max-severity SAP Netweaver flaw to deploy a persistent Linux remote access trojan (RAT) “Auto-Color.” According to a Darktrace report, a recent attack abused the flaw to set up a stealthy advanced-stage compromise but was shortly contained by its “autonomous response.” “In April 2025, Darktrace identified an […]
newswww.csoonline.comJul 29, 2025, 12:32 PMActive since at least 2023, the hacking group has been targeting the financial, government, IT, logistics, retail, and education sectors.
newswww.securityweek.comMay 29, 2025, 4:09 PMCVE-2025-31324 impacts SAP NetWeaver's Visual Composer Framework. We share our observations on this vulnerability using incident response cases and telemetry.
vendorunit42.paloaltonetworks.comMay 23, 2025, 10:00 AM- 19th May – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 19th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Fashion giant Dior confirmed a data breach that exposed customer information from its Fashion and Accessories line. The leaked data includes names, gender, phone numbers, email addresses, postal addresses, and purchase history […]
vendorresearch.checkpoint.comMay 19, 2025, 3:04 PM A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. US Government officials targeted with texts and AI-generated deepfake voice messages impersonating senior U.S. officials Shields up US […]
newssecurityaffairs.comMay 18, 2025, 11:36 AM- Week in review: Microsoft patches 5 actively exploited 0-days, recently fixed Chrome vulnerability exploitedHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Patch Tuesday: Microsoft fixes 5 actively exploited zero-days On May 2025 Patch Tuesday, Microsoft has released security fixes for 70+ vulnerabilities, among them five actively exploited zero-days and two publicly disclosed (but not exploited) vulnerabilities. How to give better cybersecurity presentations (without sounding like a robot) Most people think great presenters are born with natural talent. Luka Krejci, a presentation … More →
newswww.helpnetsecurity.comMay 18, 2025, 8:00 AM Two ransomware groups and several Chinese APTs have been exploiting two recent SAP NetWeaver vulnerabilities.
newswww.securityweek.comMay 15, 2025, 10:42 AMCISOs need to pay attention to patching five zero day Windows vulnerabilities and two other holes with available proof-of-concept exploits among the 70 fixes issued today by Microsoft in its May Patch Tuesday releases. Mike Walters, president of Action1, told CSO that leaders should focus in particular on these vulnerabilities: Screaming from hilltops? “A lot […]
newswww.csoonline.comMay 14, 2025, 12:18 AMSAP has released 16 new security notes on its May 2025 Security Patch Day, including a note dealing with another critical NetWeaver vulnerability exploited in attacks.
newswww.securityweek.comMay 13, 2025, 12:49 PMA second wave of attacks against the hundreds of SAP NetWeaver platforms compromised via CVE-2025-31324 is underway. “[The] attacks [are] staged by follow-on, opportunistic threat actors who are leveraging previously established webshells (from the first zero-day attack) on vulnerable systems,” Onapsis warned last week. The second wave of attacks CVE-2025-31324 is a vulnerability in SAP NetWeaver’s Visual Composer tool that allows unauthenticated attackers to: Upload malicious files to the host system by sending carefully crafted … More →
newswww.helpnetsecurity.comMay 12, 2025, 12:58 PMA new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Ascension reveals personal data of 437,329 patients exposed in cyberattack Operation Moonlander dismantled the botnet behind Anyproxy and […]
newssecurityaffairs.comMay 11, 2025, 6:02 PMHundreds of SAP NetWeaver instances hacked via a zero-day that allows remote code execution, not only arbitrary file uploads, as initially believed.
newswww.securityweek.comMay 9, 2025, 10:49 AMThreat actors launch second wave of attacks on SAP NetWeaver, exploiting webshells from a recent zero-day vulnerability. In April, ReliaQuest researchers warned that a zero-day vulnerability, tracked as CVE-2025-31324 (CVSS score of 10/10), in SAP NetWeaver is potentially being exploited. Thousands of internet-facing applications are potentially at risk. The flaw in SAP NetWeaver Visual Composer Metadata Uploader […]
newssecurityaffairs.comMay 6, 2025, 1:55 PMThreat actors are revisiting SAP NetWeaver instances to leverage webshells deployed via a recent zero-day vulnerability.
newswww.securityweek.comMay 6, 2025, 12:33 PMHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: RSAC 2025 Conference RSAC 2025 Conference took place at the Moscone Center in San Francisco. Check out our microsite for related news, photos, product releases, and more. Critical SAP NetWeaver flaw exploited by suspected initial access broker (CVE-2025-31324) CVE-2025-31324, a critical vulnerability in the SAP NetWeaver platform, is being actively exploited by attackers to upload malicious webshells to enable unauthorized … More →
newswww.helpnetsecurity.comMay 4, 2025, 7:42 AMU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SAP NetWeaver flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SAP NetWeaver flaw, tracked as CVE-2025-31324, to its Known Exploited Vulnerabilities (KEV) catalog. Last week, researchers warned that a zero-day vulnerability, tracked as CVE-2025-31324 (CVSS score of 10/10), in SAP NetWeaver is […]
newssecurityaffairs.comApr 30, 2025, 12:05 AM- CVE-2025-31324Horizon3.ai
SAP NetWeaver Visual Composer Metadata Uploader
exploithorizon3.aiApr 29, 2025, 3:54 PM More than 400 SAP NetWeaver servers are impacted by CVE-2025-31324, an exploited remote code execution vulnerability.
newswww.securityweek.comApr 29, 2025, 10:24 AM- Critical SAP NetWeaver flaw exploited by suspected initial access broker (CVE-2025-31324)Help Net Security
CVE-2025-31324, a critical vulnerability in the SAP NetWeaver platform, is being actively exploited by attackers to upload malicious webshells to enable unauthorized file uploads and code execution. The vulnerability was initially leveraged in zero-day attacks spotted by ReliaQuest researchers, who reported them to SAP. The software company confirmed that the attackers have been leveraging a new vulnerability, released an emergency patch on April 24, and urged organizations to upgrade to implement it and check whether … More →
newswww.helpnetsecurity.comApr 28, 2025, 9:47 AM - 28th April – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 28th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES British retailer Marks & Spencer (M&S) experienced a cyber-attack that caused disruptions to its online order system and in-store contactless payments. The company suspended online orders temporarily, refunded some customers, and reported […]
vendorresearch.checkpoint.comApr 28, 2025, 8:08 AM Attackers have been exploiting a critical zero-day vulnerability in the Visual Composer component of the SAP NetWeaver application server since early this week. SAP released an out-of-band fix that’s available through its support portal and it should be applied immediately, especially on systems that are directly exposed to the internet. “Unauthenticated attackers can abuse built-in […]
newswww.csoonline.comApr 25, 2025, 9:54 PMA zero-day in SAP NetWeaver is potentially being exploited, putting thousands of internet-facing applications at risk. Researchers warn that a zero-day vulnerability, tracked as CVE-2025-31324 (CVSS score of 10/10), in SAP NetWeaver is potentially being exploited. Thousands of internet-facing applications are potentially at risk. The flaw in SAP NetWeaver Visual Composer Metadata Uploader stems from a lack […]
newssecurityaffairs.comApr 25, 2025, 3:48 PMA zero-day vulnerability in SAP NetWeaver potentially affects more than 10,000 internet-facing applications.
newswww.securityweek.comApr 25, 2025, 9:37 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-16610CVSS 9.8 · Critical
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function.…
- CVE-2026-65885CVSS 9.4 · Critical
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into…
- CVE-2026-14270CVSS 8.8 · High
The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and inclu…
- CVE-2026-63228CVSS 2.6 · Low
An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content disguised as an image file via the feedback mail registrati…
- CVE-2026-63227CVSS 9.9 · Critical
An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessibl…
- CVE-2026-12476CVSS 7.2 · High
The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insufficient file type validation in t…