
Critical SAP S/4HANA code injection vulnerability (CVE-2025-42957) exploited in the wild – patch immediately
The exploit was discovered by the SecurityBridge Threat Research Labs, which has also verified that the exploit is being used in the wild. Immediate patching is imperative.
CVE-2025-42957 is a critical ABAP code injection flaw in SAP S/4HANA (CVSS 9.9) that allows a low-privileged user to take complete control of your SAP system.




