<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/urgent-advisory-active-exploitation-of-sap-s-4hana-vulnerability-cve-2025-42957-i1vtkkmqi" -->

---
title: Urgent Advisory: Active Exploitation of SAP S/4HANA...
description: A critical code injection vulnerability (CVE-2025-42957) with CVSS score 9.9 is being actively exploited in SAP S/4HANA systems. The flaw allows attackers with...
canonical: https://daily.dev/posts/urgent-advisory-active-exploitation-of-sap-s-4hana-vulnerability-cve-2025-42957-i1vtkkmqi
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Urgent Advisory: Active Exploitation of SAP S/4HANA Vulnerability CVE-2025-42957 | daily.dev
og:description: A critical code injection vulnerability (CVE-2025-42957) with CVSS score 9.9 is being actively exploited in SAP S/4HANA systems. The flaw allows attackers with...
og:url: https://daily.dev/posts/urgent-advisory-active-exploitation-of-sap-s-4hana-vulnerability-cve-2025-42957-i1vtkkmqi
og:image: https://api.daily.dev/og/posts/I1vtKKMQI.png
og:image:alt: Urgent Advisory: Active Exploitation of SAP S/4HANA Vulnerability CVE-2025-42957
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Urgent Advisory: Active Exploitation of SAP S/4HANA Vulnerability CVE-2025-42957

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

A critical code injection vulnerability (CVE-2025-42957) with CVSS score 9.9 is being actively exploited in SAP S/4HANA systems. The flaw allows attackers with low privileges to inject ABAP code, bypass authorization, create superuser accounts, and manipulate database data. Despite patches being available since August 11, many systems remain vulnerable due to complex ERP update processes, leading to ongoing exploitation attempts.

## Content

# Active Exploitation of Critical SAP S/4HANA Vulnerability CVE-2025-42957

A significant security flaw within SAP S/4HANA, identified as CVE-2025-42957, is currently being exploited by threat actors. With a CVSS score of 9.9, this code injection vulnerability presents a severe risk as it allows attackers with low-level privileges to inject ABAP code, bypass authorization checks, and gain complete control over the system.

## Details of the Vulnerability

The vulnerability affects all releases of SAP S/4HANA, including both on-premise and Private Cloud editions. Exploitation enables malicious actors to:
- Delete, insert, or modify critical database data.
- Create new superuser accounts with comprehensive system privileges.
- Download and potentially misuse password hashes for unauthorized access.
- Alter established business processes, potentially crippling business operations.

## Current Situation

Despite SAP releasing a patch on August 11, many systems remain unpatched. This delay can be attributed to the inherent complexities of applying security updates within ERP environments. Consequently, attackers have not only developed but also deployed working exploits, taking advantage of these unpatched systems. Notably, these exploits can delete data, escalate privileges, and cause significant operational disruptions. Security researchers, particularly those at SecurityBridge, have confirmed ongoing exploitation attempts.

## Immediate Recommendations

Organizations using SAP S/4HANA should urgently:
1. **Apply the latest security patches** provided by SAP to mitigate the vulnerability.
2. **Monitor for abnormal activity**, particularly unauthorized RFC calls or unexpected superuser account creation, which could indicate an active breach.
3. **Implement enhanced monitoring procedures** to detect unauthorized changes in business processes and system configurations.

## Conclusion

The active exploitation of CVE-2025-42957 underscores the critical importance of timely patch management and vigilant system monitoring. Organizations must prioritize securing their SAP environments to safeguard sensitive business data and maintain operational integrity.

## Similar posts on daily.dev

- [Governing Security in the Age of Infinite Signal](https://daily.dev/posts/governing-security-in-the-age-of-infinite-signal-qhihbir44) · Snyk · 0 upvotes · 0 comments
- [No one has a good plan for how AI companies should work with the government](https://daily.dev/posts/no-one-has-a-good-plan-for-how-ai-companies-should-work-with-the-government-nkajqoze1) · TechCrunch · 0 upvotes · 1 comments

---

Tags: [#security](https://daily.dev/tags/security), [#enterprise](https://daily.dev/tags/enterprise), [#vulnerability](https://daily.dev/tags/vulnerability), [#sap](https://daily.dev/tags/sap)

[View this post on daily.dev](https://daily.dev/posts/urgent-advisory-active-exploitation-of-sap-s-4hana-vulnerability-cve-2025-42957-i1vtkkmqi)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Urgent Advisory: Active Exploitation of SAP S/4HANA Vulnerability CVE-2025-42957","url":"https://daily.dev/posts/urgent-advisory-active-exploitation-of-sap-s-4hana-vulnerability-cve-2025-42957-i1vtkkmqi","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/urgent-advisory-active-exploitation-of-sap-s-4hana-vulnerability-cve-2025-42957-i1vtkkmqi"},"datePublished":"2025-09-05T11:46:56.134Z","dateModified":"2025-09-05T20:44:09.874Z","description":"A critical code injection vulnerability (CVE-2025-42957) with CVSS score 9.9 is being actively exploited in SAP S/4HANA systems. The flaw allows attackers with...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ebb38dbb3b0aba34567e5faa2d8795ce?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ebb38dbb3b0aba34567e5faa2d8795ce?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/urgent-advisory-active-exploitation-of-sap-s-4hana-vulnerability-cve-2025-42957-i1vtkkmqi","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,enterprise,vulnerability,sap","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Urgent Advisory: Active Exploitation of SAP S/4HANA Vulnerability CVE-2025-42957"}]}
```

