Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

SAP NetWeaver attacks widened beyond the original operators: What the Salt Typhoon comparison means

A 2025 SAP NetWeaver Visual Composer campaign spread beyond its suspected initial operators. Here are the vulnerabilities, timeline, victim-count limits, attribution caveats and response steps.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The SAP NetWeaver campaign was a 2025 mass-exploitation incident, not a newly emerging 2026 attack. Attackers exploited critical flaws in the Visual Composer development server, then other criminals and opportunistic operators reused exposed systems, web shells and access. Some activity was suspected to have a China nexus, but available evidence does not show that Salt Typhoon or Volt Typhoon conducted the SAP intrusions.

For SAP customers, the practical lesson is urgent but specific: determine whether Visual Composer was deployed, apply the complete SAP fix set, and investigate for compromise even if patches are now installed.

The short version for SAP customers

  • Inventory every SAP NetWeaver system and determine whether Visual Composer development-server components are installed, enabled or reachable from an untrusted network.
  • Assess SAP Security Notes 3594142 and 3604119, plus related Visual Composer fixes such as CVE-2025-42977.
  • Do not treat patch installation as proof that a previously exposed server is clean.
  • Search SAP, operating-system, proxy, firewall and authentication logs for earlier activity, including web shells, unexpected files, command execution and privilege changes.
  • Rotate SAP administrator and service-account credentials when compromise is confirmed or strongly suspected.
  • Escalate to SAP-specialist incident response if system integrity, connected interfaces or data history cannot be established.

This was exploitation of customers’ SAP software, not evidence that SAP’s own corporate network was breached or that every SAP customer was affected.

What was attacked?

SAP is the vendor. SAP NetWeaver is an application platform and middleware layer used in enterprise landscapes. Visual Composer is a development-server component within NetWeaver. A customer’s SAP environment may support finance, procurement, payroll, manufacturing, inventory, logistics and government workflows.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The principal exposure was the Visual Composer development server, associated with the VCFRAMEWORK 7.50 component signal. Independent government guidance described the component as not installed by default, although it was present or enabled in many environments. Whether an organization was exposed depended on its product version, service pack, deployment, network reachability and controls. See the CERT-FR advisory at CERT-FR.

The vulnerabilities and fixes

Vulnerability Technical issue and impact SAP response
CVE-2025-31324 Missing authorization check in the Visual Composer development server; CVSS 10.0. Reported exploitation allowed unauthenticated file uploads, web-shell deployment and command execution. Security Note 3594142, emergency release April 24, 2025. CISA added the CVE to its Known Exploited Vulnerabilities catalog on April 29, according to Onapsis.
CVE-2025-42999 Insecure deserialization in the same component; CVSS 9.1. Security Note 3604119, released May 13, 2025. Customers applying the first fix were instructed to implement this follow-up note as well.
CVE-2025-42977 Directory traversal in Visual Composer; CVSS 7.6. Listed in SAP’s May 2025 bulletin. It is related patching context, not automatically the same exploited flaw.

Use SAP’s official bulletin for applicability, support-package and version details: SAP Security Patch Day bulletins. SAP Note 3594142 was re-released on May 1, 2025 to expand support to earlier NetWeaver 7.5 service packs beginning with SP 020, according to Onapsis.

How the 2025 campaign unfolded

  1. January 20, 2025: Onapsis reportedly traced some activity to this date. That is an investigation finding, not a universal start date for every intrusion.
  2. March 2025: Google Threat Intelligence Group told CyberScoop it observed successful exploitation of one zero-day as early as March.
  3. April 22: ReliaQuest initially reported CVE-2025-31324, according to Onapsis.
  4. April 24: SAP issued emergency Note 3594142.
  5. April 29: CISA added CVE-2025-31324 to the KEV catalog, as reported by Onapsis.
  6. April 30: Onapsis said the original attackers had become quieter while other actors used public information and previously installed web shells.
  7. May 1: SAP re-released Note 3594142 with broader earlier-service-pack coverage.
  8. May 2: Onapsis and Mandiant released an open-source compromise-assessment tool and threat briefing.
  9. May 5: Responders reported a second wave of opportunistic attacks.
  10. May 13: SAP released Note 3604119 and its May security bulletin.
  11. May 15: CyberScoop reported that EclecticIQ had identified 581 victims, described as a likely partial count.

The core reporting is from April and May 2025. Nothing in the cited material establishes that this campaign was still actively expanding in August 2026.

How attackers used compromised servers

Reported activity included uploading files and web shells, executing commands, exfiltrating data, creating or adding administrators, modifying or deleting SAP data, planting executable code and weakening logs. Some attacks could execute commands without creating a conventional web shell, so a web-shell-only search can miss compromise.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

These are reported capabilities and behaviors, not a claim that every victim experienced every action. The impact depended on operating-system privileges, SAP roles, service accounts, network segmentation, interfaces and reachable connected systems.

How large was the victim population?

CyberScoop cited EclecticIQ’s count of 581 identified victims as of May 15, 2025. The publication reported that sources believed the true number could be higher. This is a time-bounded, researcher-derived and incomplete snapshot—not an audited global total, a count of confirmed data theft, or proof that all systems were compromised identically.

Reported sectors and locations included the United States, United Kingdom, Saudi Arabia, oil and gas, medical-device manufacturing, water and waste management, government agencies and other industries. The activity was not confined to one vertical. Source: CyberScoop.

Why experts mentioned Salt Typhoon and Volt Typhoon

The references are comparisons of campaign characteristics, not attribution.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Feature SAP campaign What the Typhoon comparison conveys
Confirmed group identity Not established for the whole campaign; activity involved multiple operators. Salt Typhoon and Volt Typhoon are separate threat clusters.
Initial access Exploitation of SAP NetWeaver Visual Composer vulnerabilities. Those campaigns used different access methods.
Strategic concern Enterprise, government and critical-sector SAP systems. Salt Typhoon is associated with broad communications and high-value access concerns; Volt Typhoon with critical-infrastructure access and pre-positioning concerns.
Shared concern Scale, stealth, strategic access and follow-on risk after widespread exposure. Those characteristics explain the analogy.
What cannot be inferred No evidence here establishes identical tooling, command-and-control, objectives or operators. The comparison is not proof that either Typhoon group ran the SAP intrusions.

Some activity was described as suspected China-linked or China-nexus, while later exploitation included opportunistic and potentially criminal actors. A single vulnerability can therefore support espionage, access brokerage, ransomware preparation or unrelated criminal activity at different stages.

What compromise could mean for a business

SAP systems often hold or process financial records, purchasing data, payroll, supplier and customer information, production plans, inventory and logistics. An attacker may therefore affect data confidentiality, business operations and the integrity of enterprise records—not merely steal files from an ordinary web server.

Rank #3
SAP Security and Authorizations
  • Used Book in Good Condition

That does not mean a NetWeaver compromise automatically grants unrestricted access to every connected application. Practical reach depends on segmentation, identity controls, integration accounts, interfaces and what the compromised host could access.

Why patching alone was insufficient

Exploitation began before public disclosure and patch availability. Some attackers had already installed persistence, and later actors could reuse web shells or other access. A patched system can therefore remain compromised. Monitoring that looks only for web shells can also miss alternate or fileless command execution.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CyberScoop reported that relevant maintenance could require a full reboot and that organizations were reluctant to interrupt manufacturing and financial systems. The operational requirement depends on the particular system, patch and deployment architecture; it is not a universal statement about every SAP installation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A defensive response sequence

1. Establish exposure

  • Inventory NetWeaver systems, versions, service packs and support packages.
  • Determine whether Visual Composer development-server components are installed, enabled or unused.
  • Map internet, reverse-proxy, load-balancer, remote-access and lateral-network paths.
  • For hosted or managed SAP, document which party owns patching, logs, notification and forensic access.

2. Apply the complete fix set

Assess Note 3594142 for CVE-2025-31324, Note 3604119 for CVE-2025-42999, applicable updates to those notes and related Visual Composer corrections such as CVE-2025-42977. Confirm that required service restarts or reboots occurred. Do not rely on a generic “April patch” label.

3. Hunt before and after patching

  • Search for unexpected uploaded files, web shells and executable code.
  • Review SAP application, operating-system, reverse-proxy, firewall and authentication logs.
  • Look for new administrators, privilege changes, unusual command execution and logging disruption.
  • Investigate outbound connections and unusual data transfers.
  • Compare file integrity with known-good baselines and inspect persistence that survives a restart.
  • Use the Onapsis/Mandiant assessment tool where it fits change-control and forensic procedures.

4. Protect identities and connected systems

If compromise is confirmed or strongly suspected, rotate SAP administrative credentials, service-account secrets and other credentials accessible from the host. Review privileged access, invalidate relevant tokens or keys, and investigate SAP-to-SAP and SAP-to-non-SAP integrations.

5. Contain and recover

  • Restrict internet exposure and apply temporary access controls where patching is delayed.
  • Isolate systems showing active compromise.
  • Preserve evidence before destructive cleanup.
  • Rebuild when integrity cannot be proven; validate configuration and business data changes.
  • Restore only from known-good backups after identifying the original access path.
  • Meet applicable regulatory, insurer, customer and law-enforcement notification obligations.

Questions to put to an SAP provider

  • Was Visual Composer deployed, and which versions or service packs were affected?
  • When were Notes 3594142 and 3604119 applied, and was the required restart completed?
  • Was the system internet-facing or reachable through a proxy or remote-access path?
  • Were indicators of compromise found, and were logs retained for January through May 2025?
  • Were connected identity, finance, manufacturing and supply-chain systems assessed?
  • Who owns forensic preservation, customer notification and recovery costs?

What the evidence does—and does not—show

Established: SAP NetWeaver Visual Composer vulnerabilities were exploited; SAP issued emergency and follow-up fixes; researchers observed malicious activity; and additional actors exploited exposed systems after disclosure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Not fully established: the final global victim count, the amount of data stolen from each organization, the number of operators and whether every reported victim suffered the same impact.

Analogy, not attribution: Salt Typhoon and Volt Typhoon comparisons describe breadth, stealth, strategic access and pre-positioning concerns. They do not establish that either group conducted the SAP campaign or that the incidents had identical objectives.

Primary references include SAP, Onapsis, NIST’s NVD, the Singapore Cyber Security Agency and Rapid7.

Quick Recap

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.