SAP security patch release for CVE-2025-42957
Security Patch Release
Summary
Hide ▲
Show ▼
SAP's August 2025 security updates added a patch for CVE-2025-42957, closing a critical code injection flaw in S/4HANA that affects private cloud and on-premise instances. The update matters because the flaw was already being exploited in the wild, raising the risk for unpatched systems. Administrators need to deploy the fix quickly and verify exposure to the vulnerable S/4HANA module.
Related Happenings
Progress security patch release for CVE-2026-2699
Security Patch Release
H score68
First: 02.04.2026 16:33
Last: 02.04.2026 16:33
Sources 1
About this happening:
Progress released ShareFile 5.12.4 on March 10 to fix CVE-2026-2699 and CVE-2026-2701 in the Storage Zones Controller (SZC) for branch 5.x. The update...
Progress security patch release for CVE-2026-2699
Security Patch ReleaseAbout this happening: Progress released ShareFile 5.12.4 on March 10 to fix CVE-2026-2699 and CVE-2026-2701 in the Storage Zones Controller (SZC) for branch 5.x. The update...
Oracle security patch release for CVE-2026-21992
Security Patch Release
H score44
First: 21.03.2026 12:24
Last: 21.03.2026 12:24
Sources 1
About this happening:
Oracle released security updates for CVE-2026-21992, a critical flaw in Identity Manager and Web Services Manager that could enable unauthenticated remote co...
Oracle security patch release for CVE-2026-21992
Security Patch ReleaseAbout this happening: Oracle released security updates for CVE-2026-21992, a critical flaw in Identity Manager and Web Services Manager that could enable unauthenticated remote co...
SAP security patch release for CVE-2019-17571
Security Patch Release
H score42
First: 11.03.2026 14:26
Last: 11.03.2026 14:26
Sources 1
About this happening:
SAP released security updates for two critical flaws in FS-QUO and NetWeaver Enterprise Portal Administration, reducing the risk of arbitrary code execution on...
SAP security patch release for CVE-2019-17571
Security Patch ReleaseAbout this happening: SAP released security updates for two critical flaws in FS-QUO and NetWeaver Enterprise Portal Administration, reducing the risk of arbitrary code execution on...
SolarWinds security patch release for CVE-2025-40538
Security Patch Release
H score64
First: 25.02.2026 09:04
Last: 25.02.2026 09:04
Sources 1
About this happening:
SolarWinds released Serv-U updates that fix four critical flaws in version 15.5, reducing the risk of remote code execution. The patched issues are tracked as...
SolarWinds security patch release for CVE-2025-40538
Security Patch ReleaseAbout this happening: SolarWinds released Serv-U updates that fix four critical flaws in version 15.5, reducing the risk of remote code execution. The patched issues are tracked as...
Trend Micro security patch release for CVE-2025-69258
Security Patch Release
H score39
First: 09.01.2026 12:01
Last: 09.01.2026 12:01
Sources 1
About this happening:
Trend Micro released security updates for Apex Central for Windows to fix CVE-2025-69258, a 9.8 CVSS remote-code-execution flaw that could let an unauthenticat...
Trend Micro security patch release for CVE-2025-69258
Security Patch ReleaseAbout this happening: Trend Micro released security updates for Apex Central for Windows to fix CVE-2025-69258, a 9.8 CVSS remote-code-execution flaw that could let an unauthenticat...
Timeline
-
05.09.2025 23:11 2 articles · 10mo ago
SecurityBridge verifies active exploitation of CVE-2025-42957 in SAP S/4HANA
Initial DisclosureSecurityBridge said it discovered an exploit for CVE-2025-42957 and confirmed actual abuse in SAP S/4HANA, while Pathlock detected outlier activity consistent with exploitation attempts. The flaw affects private cloud and on-premise instances, carries a 9.9 CVSS score, and SAP customers were urged to apply SAP's August 2025 security updates and restrict RFC usage with SAP's Unified Connectivity framework (UCON).
Show sources
- Critical SAP S/4HANA Vulnerability Under Attack, Patch Now — www.darkreading.com — 05.09.2025 23:11
- Critical SAP S/4HANA Vulnerability Under Attack, Patch Now — www.darkreading.com — 05.09.2025 23:11