Critical CVE-2025-31324 Flaw in SAP NetWeaver Under Active Attack

Red | Vulnerability Report
Download PDF

A critical zero-day flaw in SAP NetWeaver (CVE-2025-31324) is being actively exploited by attackers to drop web shells and run malicious code on vulnerable servers. By abusing a missing security check, threat actors can upload harmful files without logging in, making this a serious risk to any unpatched system. Users of SAP NetWeaver, update immediately and lock down access to stay protected.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox