What it is
CVE-2025-31324 is an unauthenticated vulnerability affecting SAP_SE SAP NetWeaver (Visual Composer development server). SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization,...
Vulnerability report
SAP NetWeaver (Visual Composer development server) Missing Authorization check in SAP NetWeaver
SAP SE / SAP NetWeaver (Visual Composer development server) · VCFRAMEWORK 7.50
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2025-31324 is an unauthenticated vulnerability affecting SAP_SE SAP NetWeaver (Visual Composer development server). SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization,...
Is it exploited?
Yes. KEV Intelligence sensors observed exploitation attempts with confirmed confidence.
Who is affected?
SAP_SE / SAP NetWeaver (Visual Composer development server) vcframework 7.50.
What should we do?
Patch immediately, validate internet-facing exposure, and monitor for matching requests.
Overview
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system.
This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Tenable Blog
Independent exploitation attestation added to the KEV Intelligence record.
KEV Intelligence sensor
First-party sensor telemetry confirms matching exploitation attempts.
Tenable Blog
Malware families have been linked to exploitation of this CVE.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the KEV Intelligence Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Dark Reading First | 2025-04-28 21:26 UTC |
| CISA | 2026-06-02 14:08 UTC |
| The Shadowserver | 2026-06-08 00:00 UTC |
| CVE | 2026-08-04 04:41 UTC |
| KEV Intelligence | 2026-08-09 14:50 UTC |
Operational indicators for this CVE are listed under Detection.
Sensor telemetry
Aggregate observations show the scale, recency, and distribution of activity without overstating sparse data.
13
Attempts observed
7
Unique attacker IPs
4
Attacker countries
IN · JP · NL · US
5
Sensors observed
Exploitation attempts over the last 41 days
Daily events observed by KEV Intelligence sensors
Updated 19 Aug 2026
First observed 11 Jul 2026 · Last observed 17 Aug 2026
Pro adds sensor region and window summaries. Enterprise adds raw IPs, paths, User-Agents, and payloads.
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Raw values available in Pro and Enterprise.
Nuclei template detected 16 May 2025.
View Nuclei template (opens in new tab)No KEV Intelligence virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →Attacker IP indicators observed · available in Pro and Enterprise.
Sensor-derived attacker IP indicators are available to Pro and Enterprise accounts under Detection and through the Pro API.
Learn about Pro API accessScanner and exploit-framework references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-31324.yaml | 16 May 2025 |
Risk and context
CVSS v3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
99.5%
Recent mention · Dark Reading
As threat actors continue to hop on the train of exploiting CVE-2025-31324, researchers are recommending that SAP administrators patch as soon as possible so that they don't fall victim next.
Read full advisoryRecent mention · Dark Reading
Critical SAP NetWeaver Vuln Faces Barrage of CyberattacksDark Reading · 15 May 2025
As threat actors continue to hop on the train of exploiting CVE-2025-31324, researchers are recommending that SAP administrators patch as soon as possible so that they don't fall victim next.
Recent mention · TheHackerNews
BianLian and RansomExx Exploit SAP NetWeaver Flaw to Deploy PipeMagic TrojanTheHackerNews · 14 May 2025
At least two different cybercrime groups BianLian and RansomExx are said to have exploited a recently disclosed security flaw in SAP NetWeaver tracked as CVE-2025-31324, indicating that multiple threat actors are taking advantage of the bug. Cybersecurity firm ReliaQuest, in a new update published today, said it uncovered evidence suggesting involvement from the BianLian data extortion crew and
Recent mention · TheHackerNews
China-Linked APTs Exploit SAP CVE-2025-31324 to Breach 581 Critical Systems WorldwideTheHackerNews · 13 May 2025
A recently disclosed critical security flaw impacting SAP NetWeaver is being exploited by multiple China-nexus nation-state actors to target critical infrastructure networks. "Actors leveraged CVE-2025-31324, an unauthenticated file upload vulnerability that enables remote code execution (RCE)," EclecticIQ researcher Arda Büyükkaya said in an analysis published today. Targets of the campaign
Recent mention · Palo Alto Unit42
Threat Brief: CVE-2025-31324Palo Alto Unit42 · 09 May 2025
CVE-2025-31324 impacts SAP NetWeaver's Visual Composer Framework. We share our observations on this vulnerability using incident response cases and telemetry. The post Threat Brief: CVE-2025-31324 appeared first on Unit 42.
Recent mention · TheHackerNews
Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShellTheHackerNews · 09 May 2025
A China-linked unnamed threat actor dubbed Chaya_004 has been observed exploiting a recently disclosed security flaw in SAP NetWeaver. Forescout Vedere Labs, in a report published Thursday, said it uncovered a malicious infrastructure likely associated with the hacking group weaponizing CVE-2025-31324 (CVSS score: 10.0) since April 29, 2025. CVE-2025-31324 refers to a critical SAP NetWeaver flaw
Recent mention · Horizon3.ai Attack Research
CVE-2025-31324Horizon3.ai Attack Research · 29 Apr 2025
SAP NetWeaver Visual Composer Metadata Uploader
Recent mention · All CISA Advisories
CISA Adds One Known Exploited Vulnerability to CatalogAll CISA Advisories · 29 Apr 2025
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2025-31324 SAP NetWeaver Unrestricted File Upload Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant...
Recent mention · Dark Reading
SAP NetWeaver Visual Composer Flaw Under Active ExploitationDark Reading · 28 Apr 2025
CVE-2025-31324 is a maximum severity bug that attackers exploited weeks before SAP released a patch for it.
Recent mention · Rapid7
Active exploitation of SAP NetWeaver Visual Composer CVE-2025-31324Rapid7 · 28 Apr 2025
A critical SAP NetWeaver zero-day vulnerability (CVE-2025-31324) that allows for full SAP server compromise is being actively exploited in the wild.
Recent mention · Tenable Blog
CVE-2025-31324: Zero-Day Vulnerability in SAP NetWeaver Exploited in the WildTenable Blog · 25 Apr 2025
SAP has released out-of-band patch to address CVE-2025-31324, a critical zero-day vulnerability in SAP NetWeaver that has been exploited by threat actors. Organizations are strongly encouraged to apply patches as soon as possible.BackgroundOn April 22, ReliaQuest published details of their investigation of exploit activity in SAP NetWeaver servers. Initially it was unclear if their discovery was a new vulnerability or the abuse of CVE-2017-9844, a vulnerability that could lead to a denial-of-service (DoS) condition or arbitrary code execution. ReliaQuest reported their findings to SAP and...
Recent mention · DarkWebInformer
SAP NetWeaver Vulnerability (CVE-2025-31324) Allows Remote Code Execution via File Upload FlawDarkWebInformer · 24 Apr 2025
SAP NetWeaver Vulnerability (CVE-2025-31324) Allows Remote Code Execution via File Upload Flaw
These PoCs are unverified and could contain malware. Use at your own risk.
nuclei · Created Unknown
Timeline
Exploitation attested by an external source
Evidence-backed exploitation signal
Indicators of compromise recorded
Public proof-of-concept code published
Exploitation attested by an external source
Exploit observed in malware
Listed in the CISA Known Exploited Vulnerabilities catalog
Scanner coverage available
High-confidence, third-party attested exploitation
Vulnerability disclosed publicly
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2025-31324
Free JSON includes basic KEV fields{
"cve_id": "CVE-2025-31324",
"confidence": "Confirmed",
"cvss_score": 10.0,
"cvss_estimated": false,
"epss_score": 0.99512,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": true
},
"sensor_telemetry": { "attempts": 13, "sensors": 5 }
}
Early warning alerts
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.