Critical SAP S/4HANA code injection vulnerability (CVE-2025-42957) exploited in the wild - patch immediately

Skip to content

Key Insights Blog

Read the latest insights from our experts on Cybersecurity and Risk management for SAP. 
SecurityBridge und beyond expectations schließen Partnerschaft
Press coverage

SecurityBridge und beyond expectations schließen Partnerschaft

Die beyond expectations GmbH ist neuer Partner des SAP-Sicherheits-Experten SecurityBridge für den österreichischen Markt. Der IT-Spezialist für Unternehmen mit SAP als zentraler Datendrehscheibe plant, konfiguriert und betreibt individuell entwickelte IT-Umgebungen in eigenen sowie den Rechenzentren seiner sowie auf Hyperscaler-Infrastrukturen, mit speziellem Fokus auf SAP-Lösungen.

Read More »
Events

Secure Together on the Road: Toronto 2025

SecurityBridge invites you to a day of insights and collaboration on SAP security. The program features a keynote on real-world SAP challenges, sessions on protecting on-prem and cloud systems from ransomware, securing S/4HANA with data masking and SoD controls, and aligning with SAP’s shared responsibility model. Networking opportunities, expert discussions on AI-driven identity governance, and a look ahead at the SAP GRC 2026 roadmap round out the event—closing with a vision for “Secure AI” and the future of SAP security.

Read More »
Critical SAP S4HANA code injection vulnerability (CVE-2025-42957)
SAP Vulnerability

Critical SAP S/4HANA code injection vulnerability (CVE-2025-42957) exploited in the wild – patch immediately

The exploit was discovered by the SecurityBridge Threat Research Labs, which has also verified that the exploit is being used in the wild. Immediate patching is imperative.

CVE-2025-42957 is a critical ABAP code injection flaw in SAP S/4HANA (CVSS 9.9) that allows a low-privileged user to take complete control of your SAP system.

Read More »