
A new vulnerability in SAP NetWeaver servers has triggered a serious security concern. According to a report by BleepingComputer, over 1,200 internet-exposed systems have been identified as vulnerable, and almost 500 are already compromised.
SAP NetWeaver, widely used by enterprises to connect and run both SAP and non-SAP applications, has been found to contain a critical unauthenticated file upload flaw (CVE-2025-31324). This vulnerability affects the Visual Composer’s Metadata Uploader component and enables remote attackers to upload arbitrary executable files without any authentication.