Target Industry

Indiscriminate, opportunistic targeting. 

Overview

SAP issued a total of 26 security notes as part of its September 2025 Security Patch Day, including four categorised as HotNews due to their critical severity. Among the most significant vulnerabilities are those involving insecure deserialisation in SAP NetWeaver and insecure file operations in SAP NetWeaver AS Java.  

Below lists the four HotNews vulnerabilities and four high-priority vulnerabilities addressed: 

  • Critical Vulnerabilities 
  • CVE-2025-42944 (CVSS 10.0) – Insecure deserialisation in SAP NetWeaver allows remote code execution 
  • CVE-2025-42922 (CVSS 9.9) – Insecure file operations in SAP NetWeaver AS Java enable unauthorised access 
  • CVE-2023-27500 (CVSS 9.6) – Directory traversal in SAP NetWeaver AS ABAP may lead to system compromise 
  • CVE-2025-42958 (CVSS 9.1) – Missing authentication check in SAP NetWeaver allows privilege escalation 
  • High-Priority Vulnerabilities 
  • CVE-2025-42933 (CVSS 8.8) – Insecure storage in SAP Business One could expose sensitive data 
  • CVE-2025-42929 (CVSS 8.1) – Input validation flaw in SAP LT Replication Server risks data integrity 
  • CVE-2025-42916 (CVSS 8.1) – Input validation issue in SAP S/4HANA may allow unauthorised actions 
  • CVE-2025-27428 (CVSS 7.7) – Security misconfiguration in SAP NetWeaver AS ABAP affects system stability 

Impact

The vulnerabilities can lead to significant operational disruptions, data breaches, and financial losses. For instance, CVE-2025-42944 allows unauthenticated threat actors to execute arbitrary commands, potentially leading to full system compromise. The financial implications can be severe, with potential costs associated with data recovery, regulatory fines, and reputational damage. 

Exploitation

Exploitation of these vulnerabilities can occur through methods such as sending crafted requests to vulnerable endpoints or utilising insecure deserialisation techniques. Threat actors may leverage tools to automate the exploitation process, especially for vulnerabilities with high CVSS scores. 

Containment, Mitigations & Remediations

To mitigate these vulnerabilities, SAP recommends applying the latest security patches immediately. Organisations should also implement network segmentation, restrict access to sensitive components, and conduct regular security audits. 

Threat Landscape

The threat landscape for SAP systems is evolving, with increasingly sophisticated attack methods. Threat actors are motivated by financial gain, espionage, and disruption of services. The active exploitation of vulnerabilities like CVE-2025-42957 highlights the urgent need for organisations to prioritise security. 

Threat Group

Threat groups targeting SAP vulnerabilities often include cybercriminal organisations and state-sponsored actors. These groups utilise sophisticated tactics, including social engineering and automated tools, to exploit vulnerabilities in SAP systems. 

Further Information

Intelligence Terminology Yardstick

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content