
SAP has announced massive security updates, addressing several critical vulnerabilities across its enterprise software portfolio. The most urgent fixes target two zero-day flaws in SAP NetWeaver Visual Composer, which attackers have already exploited.
The vulnerabilities, identified as CVE-2025-31324 and CVE-2025-42999, allow unauthenticated attackers to remotely upload and execute malicious files on vulnerable SAP servers. Security experts warn that these flaws could lead to full system compromise, data theft, and service disruption if left unpatched.