SAP’s May 2025 Security Patch Day includes an urgent update to the previously released emergency patch for a critical zero-day vulnerability (CVE-2025-31324) that continues to see active exploitation across multiple industries globally. With the vulnerability granting attackers “<sid>adm access” to underlying SAP operating systems, compromised environments face risks of data theft, financial record manipulation, ransomware deployment, and potential regulatory compliance violations. The vulnerability’s impact spans numerous sectors, with Onapsis and Mandiant confirming “exploitation across industries and geographies, including confirmed compromises at energy and utilities, manufacturing, media and entertainment, oil and gas, pharmaceuticals, retail and government organizations”. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. The release includes 16 new Security Notes and 2 updates to previously released notes, with special emphasis on addressing the severe NetWeaver vulnerability. First reported by security research firm ReliaQuest on April 22, 2025, the flaw prompted SAP to issue an emergency patch on April 24. This vulnerability is particularly dangerous because it allows unauthenticated remote attackers to upload arbitrary files, including malicious executables, resulting in complete system compromise.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 13 May 2025 10:30:09 +0000