You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2025-31324
About this tag
CVE-2025-31324 is a critical unrestricted file upload vulnerability affecting SAP NetWeaver. It was added to CISA's Known Exploited Vulnerabilities Catalog in April 2025 after verified active exploitation. Enterprise IT teams, particularly in federal agencies, are urged to prioritize patching this flaw as part of their Patch Tuesday risk management. Discussions on WindowsForum highlight the urgency of addressing this SAP vulnerability alongside other high-severity CVEs, emphasizing the need for immediate remediation to prevent exploitation.
September’s Patch Tuesday delivered a predictable mix of Windows fixes and the usual Office headaches — but this month the spotlight belongs to SAP, where a string of actively exploited and high-severity NetWeaver flaws demand an urgent, prioritized response from enterprise teams.
Background...
In another development underscoring the persistent and ever-evolving nature of cyber threats, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of a new entry to its Known Exploited Vulnerabilities Catalog. This action, recorded on April 29, 2025...