#NetWeaver
SAP NetWeaver Extended Passport Remote Code Execution https://packetstorm.news/files/232401 #exploit
September 24, 2026 at 12:33 AM
It looks like there's a SAP NetWeaver zero-day in the wild:

reliaquest.com/blog/threat-...

SAP advisory (via cr0w on Mastodon): me.sap.com/notes/3594142
ReliaQuest Uncovers Potential New Vulnerability in SAP NetWeaver
ReliaQuest has observed SAP NetWeaver incidents with unauthorized file uploads and malicious execution, hinting at a possible unreported vulnerability.
reliaquest.com
April 24, 2025 at 6:44 PM
Critical vulnerability in SAP NetWeaver enables malicious file uploads
Critical vulnerability in SAP NetWeaver enables malicious file uploads
Adversaries can exploit CVE-2025-31324 to upload web shells and other unauthorized files to execute on the SAP NetWeaver server
redcanary.com
May 1, 2025 at 3:40 AM
SAP NetWeaver Vulnerabilities Let Attackers Upload Malicious PDF Files
SAP NetWeaver Vulnerabilities Let Attackers Upload Malicious PDF Files
SAP has issued a crucial security update addressing multiple high-severity vulnerabilities in its NetWeaver Application Server for Java, specifically within the Adobe Document Services component.
cybersecuritynews.com
December 10, 2024 at 2:28 PM
I had to check but yes, this is a brand new NetWeaver perfect 10, among others:
SAP fixes maximum severity NetWeaver command execution flaw
SAP has addressed 21 new vulnerabilities affecting its products, including three critical severity issues impacting the NetWeaver software solution.
www.bleepingcomputer.com
September 9, 2025 at 1:28 PM
This is not just an RCE, it's a [popular British supermarket] RCE reliaquest.com/blog/threat-...
ReliaQuest Uncovers New Critical Vulnerability in SAP NetWeaver
ReliaQuest has uncovered a new vulnerability in SAP NetWeaver, CVE-2025-31324, involving unauthorized file uploads and malicious execution.
reliaquest.com
April 26, 2025 at 10:12 AM
SAP NetWeaver delivers the technical foundation for integration, application development and system-wide consistency, and the Info-Cube introduces these capabilities as part of a comprehensive orientation hub.

s4-experts.com/sap-abap-sof...

#SAP #NetWeaver #SAPNW #SAPNetWeaver #middleware
November 22, 2025 at 10:08 AM
SAP NetWeaver delivers the technical foundation for integration, application development and system-wide consistency, and the Info-Cube introduces these capabilities as part of a comprehensive orientation hub.

s4-experts.com/sap-abap-sof...

#SAP #NetWeaver #SAPNW #SAPNetWeaver #middleware
November 22, 2025 at 10:08 AM
Over 1,200 internet-exposed SAP NetWeaver instances are vulnerable to an actively exploited maximum severity unauthenticated file upload vulnerability that allows attackers to hijack servers.
Over 1,200 SAP NetWeaver servers vulnerable to actively exploited flaw
Over 1,200 internet-exposed SAP NetWeaver instances are vulnerable to an actively exploited maximum severity unauthenticated file upload vulnerability that allows attackers to hijack servers.
www.bleepingcomputer.com
April 28, 2025 at 4:47 PM
New Blog Post:
Calling ABAP function modules from Node.js or SAP CAP should not require the SAP NetWeaver RFC SDK. That is why I built open-rfc: an open-source, dependency-free client that also works on SAP BTP through Cloud Connector.

Read here: blog.zeis.de/posts/2026-0...
August 10, 2026 at 1:36 PM
SAP NetWeaver delivers the technical foundation for integration, application development and system-wide consistency, and the Info-Cube introduces these capabilities as part of a comprehensive orientation hub.

s4-experts.com/sap-abap-sof...

#SAP #NetWeaver #SAPNW #SAPNetWeaver #middleware
SAP ABAP Softwareentwickler
Als Netzwerkorganisation decken wir durch unsere zahlreichen Partner alle SAP-Systeme und -Module ab. Wir bauen unseren öffentlichen Anteil am Wissensmanagement kontinuierlich aus. Einige Bereiche …
s4-experts.com
November 22, 2025 at 10:08 AM
#Doom II: Valiant - MAP13: The Netweaver (Ultra-Violence 100%)
decino
www.youtube.com/watch?v=ZIYg...
Doom II: Valiant - MAP13: The Netweaver (Ultra-Violence 100%)
YouTube video by decino
www.youtube.com
December 16, 2024 at 3:25 PM
China-backed hackers are on the move.

Earth Lamia is hitting govts, IT firms & universities in 🇮🇳 🇧🇷 🇻🇳 🇵🇭 🇹🇭 using 9 exploits—incl. SAP NetWeaver & TeamCity.

⚠️ SQL injections
⚠️ Custom malware
⚠️ Ransomware… then delete it?
#CyberAttacks
thehackernews.com/2025/05/chin...
China-Linked Hackers Exploit SAP and SQL Server Flaws in Attacks Across Asia and Brazil
Earth Lamia exploited SAP NetWeaver CVE-2025-31324 to breach Asian and Brazilian orgs since 2023.
thehackernews.com
June 1, 2025 at 4:29 AM
Attention! We are sharing SAP NetWeaver instances vulnerable to CVE-2025-31324 unauth upload (CVSS 10.0). 454 IPs found vulnerable on 2025-04-26. If you receive an alert from us, make sure to check for signs of compromise (incl. webshells).

World Map: dashboard.shadowserver.org/statistics/c...
April 27, 2025 at 4:31 PM
SAP releases critical patches for NetWeaver vulnerabilities. Administrators urged to update systems promptly to prevent potential exploits. #SAP #NetWeaver #CyberSecurity #PatchNow Link: thedailytechfeed.com/sap-releases...
September 9, 2025 at 4:16 PM
Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware
Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware
cybersecuritynews.com
July 30, 2025 at 8:16 AM
SAP Billing keeping it safe...

Min 30 characters password 😲
But then not longer than 41 characters 😂

PS: Good ol' NetWeaver, of course. Guess it's not that easy to upgrade to S/4 or whatever.
January 28, 2026 at 6:44 PM
Hackers were spotted exploiting a critical SAP NetWeaver vulnerability tracked as CVE-2025-31324 to deploy the Auto-Color Linux malware in a cyberattack on a U.S.-based chemicals company.
Hackers exploit SAP NetWeaver bug to deploy Linux Auto-Color malware
Hackers were spotted exploiting a critical SAP NetWeaver vulnerability tracked as CVE-2025-31324 to deploy the Auto-Color Linux malware in a cyberattack on a U.S.-based chemicals company.
www.bleepingcomputer.com
July 29, 2025 at 4:10 PM