Vulnerability report

Active exploitation observed Confirmed confidence In CISA KEV

CVE-2025-31324

SAP NetWeaver (Visual Composer development server) Missing Authorization check in SAP NetWeaver

SAP SE / SAP NetWeaver (Visual Composer development server) · VCFRAMEWORK 7.50

Severity
CVSS 10.0 · Critical
Confidence
Confirmed
Exploit status
Observed in sensors
EPSS
99.5%
First observed
11 Jul 2026
Last observed
17 Aug 2026

Decision summary

What security teams need to know first

Direct answers before the deeper technical record.

What it is

CVE-2025-31324 is an unauthenticated vulnerability affecting SAP_SE SAP NetWeaver (Visual Composer development server). SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization,...

Is it exploited?

Yes. KEV Intelligence sensors observed exploitation attempts with confirmed confidence.

Who is affected?

SAP_SE / SAP NetWeaver (Visual Composer development server) vcframework 7.50.

What should we do?

Patch immediately, validate internet-facing exposure, and monitor for matching requests.

Overview

SAP NetWeaver (Visual Composer development server) Missing Authorization check in SAP NetWeaver

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system.

This could significantly affect the confidentiality, integrity, and availability of the targeted system.

Vendor Product Affected Status
SAP_SE SAP NetWeaver (Visual Composer development server) VCFRAMEWORK 7.50 Affected
Published
24 Apr 2025
Exploitation Reported
25 Apr 2025
Attack vector
Remote
Complexity
Low
Privileges
None
User interaction
None

Tags

windows cisa nuclei_scanner malware

CVE References

Exploitation evidence

Why KEV Intelligence marks this CVE as exploited

Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.

Exploited in the wild

Tenable Blog

Recorded 25 Apr 2025

Independent exploitation attestation added to the KEV Intelligence record.

Active exploitation observed

KEV Intelligence sensor

First observed 11 Jul 2026

First-party sensor telemetry confirms matching exploitation attempts.

Used in malware

Tenable Blog

Recorded 02 Jun 2026

Malware families have been linked to exploitation of this CVE.

Proof of concept available

GitHub

Recorded 25 Apr 2025

Public scanner or PoC coverage increases practical exploitability.

Known exploited vulnerability sources

Per-source evidence links for KEV attestations are available through the KEV Intelligence Pro API.

Learn about Pro API access
Source Added
Dark Reading First 2025-04-28 21:26 UTC
CISA 2026-06-02 14:08 UTC
The Shadowserver 2026-06-08 00:00 UTC
CVE 2026-08-04 04:41 UTC
KEV Intelligence 2026-08-09 14:50 UTC

Operational indicators for this CVE are listed under Detection.

Sensor telemetry

First-party evidence of exploitation activity

Aggregate observations show the scale, recency, and distribution of activity without overstating sparse data.

13

Attempts observed

7

Unique attacker IPs

4

Attacker countries

IN · JP · NL · US

5

Sensors observed

Exploitation attempts over the last 41 days

Daily events observed by KEV Intelligence sensors

Updated 19 Aug 2026

0
1
1
1
1
0
1
1
1
1
0
0
0
1
0
0
0
0
2
0
2
0
0
0
0
0
0
0
0
3
0
0
0
2
0
0
0
1
2
0
0
10 Jul 19 Jul 28 Jul 6 Aug 19 Aug

First observed 11 Jul 2026 · Last observed 17 Aug 2026

Pro adds sensor region and window summaries. Enterprise adds raw IPs, paths, User-Agents, and payloads.

Request telemetry access

Detection

Operational artifacts and observed signals

Make the evidence actionable in scanner, SOC, and edge-control workflows.

Observed signals

Request targets
2
User-Agents
12

Raw values available in Pro and Enterprise.

Virtual patch status

No KEV Intelligence virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.

Learn about virtual patches →

Attacker IP Indicators

Attacker IP indicators observed · available in Pro and Enterprise.

Sensor-derived attacker IP indicators are available to Pro and Enterprise accounts under Detection and through the Pro API.

Learn about Pro API access

Scanner Artifacts

Scanner and exploit-framework references linked to this CVE.

Risk and context

Severity, weaknesses, and research context

CVSS v3.1

10.0 Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS

99.5%

Recent mention · Dark Reading

Critical SAP NetWeaver Vuln Faces Barrage of Cyberattacks

As threat actors continue to hop on the train of exploiting CVE-2025-31324, researchers are recommending that SAP administrators patch as soon as possible so that they don't fall victim next.

Read full advisory

All Mentions

Recent mention · Dark Reading

Critical SAP NetWeaver Vuln Faces Barrage of Cyberattacks

Dark Reading · 15 May 2025

As threat actors continue to hop on the train of exploiting CVE-2025-31324, researchers are recommending that SAP administrators patch as soon as possible so that they don't fall victim next.

Recent mention · TheHackerNews

BianLian and RansomExx Exploit SAP NetWeaver Flaw to Deploy PipeMagic Trojan

TheHackerNews · 14 May 2025

At least two different cybercrime groups BianLian and RansomExx are said to have exploited a recently disclosed security flaw in SAP NetWeaver tracked as CVE-2025-31324, indicating that multiple threat actors are taking advantage of the bug. Cybersecurity firm ReliaQuest, in a new update published today, said it uncovered evidence suggesting involvement from the BianLian data extortion crew and

Recent mention · TheHackerNews

China-Linked APTs Exploit SAP CVE-2025-31324 to Breach 581 Critical Systems Worldwide

TheHackerNews · 13 May 2025

A recently disclosed critical security flaw impacting SAP NetWeaver is being exploited by multiple China-nexus nation-state actors to target critical infrastructure networks. "Actors leveraged CVE-2025-31324, an unauthenticated file upload vulnerability that enables remote code execution (RCE)," EclecticIQ researcher Arda Büyükkaya said in an analysis published today. Targets of the campaign

Recent mention · Palo Alto Unit42

Threat Brief: CVE-2025-31324

Palo Alto Unit42 · 09 May 2025

CVE-2025-31324 impacts SAP NetWeaver's Visual Composer Framework. We share our observations on this vulnerability using incident response cases and telemetry. The post Threat Brief: CVE-2025-31324 appeared first on Unit 42.

Recent mention · TheHackerNews

Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell

TheHackerNews · 09 May 2025

A China-linked unnamed threat actor dubbed Chaya_004 has been observed exploiting a recently disclosed security flaw in SAP NetWeaver. Forescout Vedere Labs, in a report published Thursday, said it uncovered a malicious infrastructure likely associated with the hacking group weaponizing CVE-2025-31324 (CVSS score: 10.0) since April 29, 2025. CVE-2025-31324 refers to a critical SAP NetWeaver flaw

Recent mention · Horizon3.ai Attack Research

CVE-2025-31324

Horizon3.ai Attack Research · 29 Apr 2025

SAP NetWeaver Visual Composer Metadata Uploader

Recent mention · All CISA Advisories

CISA Adds One Known Exploited Vulnerability to Catalog

All CISA Advisories · 29 Apr 2025

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2025-31324 SAP NetWeaver Unrestricted File Upload Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant...

Recent mention · Dark Reading

SAP NetWeaver Visual Composer Flaw Under Active Exploitation

Dark Reading · 28 Apr 2025

CVE-2025-31324 is a maximum severity bug that attackers exploited weeks before SAP released a patch for it.

Recent mention · Rapid7

Active exploitation of SAP NetWeaver Visual Composer CVE-2025-31324

Rapid7 · 28 Apr 2025

A critical SAP NetWeaver zero-day vulnerability (CVE-2025-31324) that allows for full SAP server compromise is being actively exploited in the wild.

Recent mention · Tenable Blog

CVE-2025-31324: Zero-Day Vulnerability in SAP NetWeaver Exploited in the Wild

Tenable Blog · 25 Apr 2025

SAP has released out-of-band patch to address CVE-2025-31324, a critical zero-day vulnerability in SAP NetWeaver that has been exploited by threat actors. Organizations are strongly encouraged to apply patches as soon as possible.BackgroundOn April 22, ReliaQuest published details of their investigation of exploit activity in SAP NetWeaver servers. Initially it was unclear if their discovery was a new vulnerability or the abuse of CVE-2017-9844, a vulnerability that could lead to a denial-of-service (DoS) condition or arbitrary code execution. ReliaQuest reported their findings to SAP and...

Recent mention · DarkWebInformer

SAP NetWeaver Vulnerability (CVE-2025-31324) Allows Remote Code Execution via File Upload Flaw

DarkWebInformer · 24 Apr 2025

SAP NetWeaver Vulnerability (CVE-2025-31324) Allows Remote Code Execution via File Upload Flaw

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

Timeline

From disclosure to observed exploitation

  1. KEV confirmed by CVE

    Exploitation attested by an external source

  2. Observed by KEV Intelligence sensors

    Evidence-backed exploitation signal

  3. Indicators of compromise added (12)

    Indicators of compromise recorded

  4. Public PoC available

    Public proof-of-concept code published

  5. KEV confirmed by The Shadowserver

    Exploitation attested by an external source

  6. First public exploitation report

    Exploit observed in malware

  7. Added to CISA KEV

    Listed in the CISA Known Exploited Vulnerabilities catalog

  8. Nuclei template available

    Scanner coverage available

  9. Added to KEV Intelligence KEV Feed

    High-confidence, third-party attested exploitation

  10. CVE published

    Vulnerability disclosed publicly

  11. CVE ID reserved

    Identifier reserved by the CNA

Pro API

Automate this intelligence

Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.

  • Evidence confidence and provenance
  • First-party sensor telemetry
  • PoC and scanner references
  • Affected versions and enrichment
  • Automation-ready JSON delivery

GET /api/v2/pro/kevs/CVE-2025-31324

Free JSON includes basic KEV fields
{
  "cve_id": "CVE-2025-31324",
  "confidence": "Confirmed",
  "cvss_score": 10.0,
  "cvss_estimated": false,
  "epss_score": 0.99512,
  "exploit_status": {
    "exploited_in_the_wild": true,
    "active_exploitation_observed": true
  },
  "sensor_telemetry": { "attempts": 13, "sensors": 5 }
}

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.