The SAP NetWeaver campaign was a 2025 mass-exploitation incident, not a newly emerging 2026 attack. Attackers exploited critical flaws in the Visual Composer development server, then other criminals and opportunistic operators reused exposed systems, web shells and access. Some activity was suspected to have a China nexus, but available evidence does not show that Salt Typhoon or Volt Typhoon conducted the SAP intrusions.
For SAP customers, the practical lesson is urgent but specific: determine whether Visual Composer was deployed, apply the complete SAP fix set, and investigate for compromise even if patches are now installed.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
SAP System Security Guide (SAP PRESS) | $67.49 | Buy on Amazon |
| 2 |
|
Mastering SAP: Protecting your SAP environment in Today's Cybersecurity World | $9.99 | Buy on Amazon |
| 3 |
|
SAP Security and Authorizations | $17.57 | Buy on Amazon |
| 4 |
|
Beginner's Guide to SAP Security and Authorizations | $19.95 | Buy on Amazon |
The short version for SAP customers
- Inventory every SAP NetWeaver system and determine whether Visual Composer development-server components are installed, enabled or reachable from an untrusted network.
- Assess SAP Security Notes 3594142 and 3604119, plus related Visual Composer fixes such as CVE-2025-42977.
- Do not treat patch installation as proof that a previously exposed server is clean.
- Search SAP, operating-system, proxy, firewall and authentication logs for earlier activity, including web shells, unexpected files, command execution and privilege changes.
- Rotate SAP administrator and service-account credentials when compromise is confirmed or strongly suspected.
- Escalate to SAP-specialist incident response if system integrity, connected interfaces or data history cannot be established.
This was exploitation of customers’ SAP software, not evidence that SAP’s own corporate network was breached or that every SAP customer was affected.
What was attacked?
SAP is the vendor. SAP NetWeaver is an application platform and middleware layer used in enterprise landscapes. Visual Composer is a development-server component within NetWeaver. A customer’s SAP environment may support finance, procurement, payroll, manufacturing, inventory, logistics and government workflows.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
The principal exposure was the Visual Composer development server, associated with the VCFRAMEWORK 7.50 component signal. Independent government guidance described the component as not installed by default, although it was present or enabled in many environments. Whether an organization was exposed depended on its product version, service pack, deployment, network reachability and controls. See the CERT-FR advisory at CERT-FR.
The vulnerabilities and fixes
| Vulnerability | Technical issue and impact | SAP response |
|---|---|---|
| CVE-2025-31324 | Missing authorization check in the Visual Composer development server; CVSS 10.0. Reported exploitation allowed unauthenticated file uploads, web-shell deployment and command execution. | Security Note 3594142, emergency release April 24, 2025. CISA added the CVE to its Known Exploited Vulnerabilities catalog on April 29, according to Onapsis. |
| CVE-2025-42999 | Insecure deserialization in the same component; CVSS 9.1. | Security Note 3604119, released May 13, 2025. Customers applying the first fix were instructed to implement this follow-up note as well. |
| CVE-2025-42977 | Directory traversal in Visual Composer; CVSS 7.6. | Listed in SAP’s May 2025 bulletin. It is related patching context, not automatically the same exploited flaw. |
Use SAP’s official bulletin for applicability, support-package and version details: SAP Security Patch Day bulletins. SAP Note 3594142 was re-released on May 1, 2025 to expand support to earlier NetWeaver 7.5 service packs beginning with SP 020, according to Onapsis.
How the 2025 campaign unfolded
- January 20, 2025: Onapsis reportedly traced some activity to this date. That is an investigation finding, not a universal start date for every intrusion.
- March 2025: Google Threat Intelligence Group told CyberScoop it observed successful exploitation of one zero-day as early as March.
- April 22: ReliaQuest initially reported CVE-2025-31324, according to Onapsis.
- April 24: SAP issued emergency Note 3594142.
- April 29: CISA added CVE-2025-31324 to the KEV catalog, as reported by Onapsis.
- April 30: Onapsis said the original attackers had become quieter while other actors used public information and previously installed web shells.
- May 1: SAP re-released Note 3594142 with broader earlier-service-pack coverage.
- May 2: Onapsis and Mandiant released an open-source compromise-assessment tool and threat briefing.
- May 5: Responders reported a second wave of opportunistic attacks.
- May 13: SAP released Note 3604119 and its May security bulletin.
- May 15: CyberScoop reported that EclecticIQ had identified 581 victims, described as a likely partial count.
The core reporting is from April and May 2025. Nothing in the cited material establishes that this campaign was still actively expanding in August 2026.
How attackers used compromised servers
Reported activity included uploading files and web shells, executing commands, exfiltrating data, creating or adding administrators, modifying or deleting SAP data, planting executable code and weakening logs. Some attacks could execute commands without creating a conventional web shell, so a web-shell-only search can miss compromise.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
These are reported capabilities and behaviors, not a claim that every victim experienced every action. The impact depended on operating-system privileges, SAP roles, service accounts, network segmentation, interfaces and reachable connected systems.
How large was the victim population?
CyberScoop cited EclecticIQ’s count of 581 identified victims as of May 15, 2025. The publication reported that sources believed the true number could be higher. This is a time-bounded, researcher-derived and incomplete snapshot—not an audited global total, a count of confirmed data theft, or proof that all systems were compromised identically.
Reported sectors and locations included the United States, United Kingdom, Saudi Arabia, oil and gas, medical-device manufacturing, water and waste management, government agencies and other industries. The activity was not confined to one vertical. Source: CyberScoop.
Why experts mentioned Salt Typhoon and Volt Typhoon
The references are comparisons of campaign characteristics, not attribution.
| Feature | SAP campaign | What the Typhoon comparison conveys |
|---|---|---|
| Confirmed group identity | Not established for the whole campaign; activity involved multiple operators. | Salt Typhoon and Volt Typhoon are separate threat clusters. |
| Initial access | Exploitation of SAP NetWeaver Visual Composer vulnerabilities. | Those campaigns used different access methods. |
| Strategic concern | Enterprise, government and critical-sector SAP systems. | Salt Typhoon is associated with broad communications and high-value access concerns; Volt Typhoon with critical-infrastructure access and pre-positioning concerns. |
| Shared concern | Scale, stealth, strategic access and follow-on risk after widespread exposure. | Those characteristics explain the analogy. |
| What cannot be inferred | No evidence here establishes identical tooling, command-and-control, objectives or operators. | The comparison is not proof that either Typhoon group ran the SAP intrusions. |
Some activity was described as suspected China-linked or China-nexus, while later exploitation included opportunistic and potentially criminal actors. A single vulnerability can therefore support espionage, access brokerage, ransomware preparation or unrelated criminal activity at different stages.
What compromise could mean for a business
SAP systems often hold or process financial records, purchasing data, payroll, supplier and customer information, production plans, inventory and logistics. An attacker may therefore affect data confidentiality, business operations and the integrity of enterprise records—not merely steal files from an ordinary web server.
Rank #3
- Used Book in Good Condition
That does not mean a NetWeaver compromise automatically grants unrestricted access to every connected application. Practical reach depends on segmentation, identity controls, integration accounts, interfaces and what the compromised host could access.
Why patching alone was insufficient
Exploitation began before public disclosure and patch availability. Some attackers had already installed persistence, and later actors could reuse web shells or other access. A patched system can therefore remain compromised. Monitoring that looks only for web shells can also miss alternate or fileless command execution.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteCyberScoop reported that relevant maintenance could require a full reboot and that organizations were reluctant to interrupt manufacturing and financial systems. The operational requirement depends on the particular system, patch and deployment architecture; it is not a universal statement about every SAP installation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.A defensive response sequence
1. Establish exposure
- Inventory NetWeaver systems, versions, service packs and support packages.
- Determine whether Visual Composer development-server components are installed, enabled or unused.
- Map internet, reverse-proxy, load-balancer, remote-access and lateral-network paths.
- For hosted or managed SAP, document which party owns patching, logs, notification and forensic access.
2. Apply the complete fix set
Assess Note 3594142 for CVE-2025-31324, Note 3604119 for CVE-2025-42999, applicable updates to those notes and related Visual Composer corrections such as CVE-2025-42977. Confirm that required service restarts or reboots occurred. Do not rely on a generic “April patch” label.
3. Hunt before and after patching
- Search for unexpected uploaded files, web shells and executable code.
- Review SAP application, operating-system, reverse-proxy, firewall and authentication logs.
- Look for new administrators, privilege changes, unusual command execution and logging disruption.
- Investigate outbound connections and unusual data transfers.
- Compare file integrity with known-good baselines and inspect persistence that survives a restart.
- Use the Onapsis/Mandiant assessment tool where it fits change-control and forensic procedures.
4. Protect identities and connected systems
If compromise is confirmed or strongly suspected, rotate SAP administrative credentials, service-account secrets and other credentials accessible from the host. Review privileged access, invalidate relevant tokens or keys, and investigate SAP-to-SAP and SAP-to-non-SAP integrations.
5. Contain and recover
- Restrict internet exposure and apply temporary access controls where patching is delayed.
- Isolate systems showing active compromise.
- Preserve evidence before destructive cleanup.
- Rebuild when integrity cannot be proven; validate configuration and business data changes.
- Restore only from known-good backups after identifying the original access path.
- Meet applicable regulatory, insurer, customer and law-enforcement notification obligations.
Questions to put to an SAP provider
- Was Visual Composer deployed, and which versions or service packs were affected?
- When were Notes 3594142 and 3604119 applied, and was the required restart completed?
- Was the system internet-facing or reachable through a proxy or remote-access path?
- Were indicators of compromise found, and were logs retained for January through May 2025?
- Were connected identity, finance, manufacturing and supply-chain systems assessed?
- Who owns forensic preservation, customer notification and recovery costs?
What the evidence does—and does not—show
Established: SAP NetWeaver Visual Composer vulnerabilities were exploited; SAP issued emergency and follow-up fixes; researchers observed malicious activity; and additional actors exploited exposed systems after disclosure.
Recommended Free Tools
Not fully established: the final global victim count, the amount of data stolen from each organization, the number of operators and whether every reported victim suffered the same impact.
Analogy, not attribution: Salt Typhoon and Volt Typhoon comparisons describe breadth, stealth, strategic access and pre-positioning concerns. They do not establish that either group conducted the SAP campaign or that the incidents had identical objectives.
Primary references include SAP, Onapsis, NIST’s NVD, the Singapore Cyber Security Agency and Rapid7.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




