Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical SAP S/4HANA Vulnerability Actively Exploited to Fully Compromise Your SAP System

A critical vulnerability in SAP S/4HANA is being actively exploited, allowing attackers with low-level user access to gain complete control over affected systems.

A critical vulnerability in SAP S/4HANA is being actively exploited, allowing attackers with low-level user access to gain complete control over affected systems.

The vulnerability, identified as CVE-2025-42957 , carries a CVSS score of 9.9 out of 10, indicating a severe threat to organizations using all releases of S/4HANA, both on-premise and in private clouds.

The flaw was discovered by researchers at SecurityBridge Threat Research Labs, who have confirmed its active exploitation by malicious actors.

SAP released a patch on Fri, Aug 11, 2025, and it is strongly recommended that all customers apply the security updates immediately.

This ABAP code injection vulnerability allows attackers to gain full administrative privileges, granting access to the underlying operating system and control over all data within the SAP system.

The potential consequences include theft of sensitive business information, financial fraud, espionage, and ransomware deployment.

The flaw was discovered by researchers at SecurityBridge Threat Research Labs, who have confirmed its active exploitation by malicious actors.
Emily Carter · Thehackingpost

An attacker can delete or insert data directly into the database, create new administrator accounts with SAP_ALL privileges, download password hashes, and modify core business processes with minimal effort.

The low attack complexity of CVE-2025-42957 makes it particularly dangerous, as an attacker needs only a low-privileged user account, which can be obtained through phishing or other common methods.

Once access is acquired, the flaw can be exploited over the network without user interaction, escalating privileges to achieve a full system compromise.

SecurityBridge, which responsibly disclosed the vulnerability to SAP on Fri, Jun 27, 2025, warns that unpatched systems are at immediate risk.

Advertisement

Due to the open nature of SAP’s ABAP code, reverse engineering the patch to create a working exploit is relatively simple for skilled attackers.

Security experts recommend the following measures for organizations to protect themselves:

Patch Immediately: Apply SAP’s August 2025 security updates, specifically SAP Notes 3627998 and 3633838, without delay. Review Access: Restrict access to the S_DMIS authorization object and consider implementing SAP UCON to limit RFC usage. Monitor System Logs: Actively watch for suspicious RFC calls, the creation of new high-privilege users, or unexpected changes to ABAP code. Harden Defenses: Ensure robust system segmentation, regular backups, and SAP-specific security monitoring solutions are in place to detect and respond to attacks.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories