SAP security patch release for CVE-2025-42944
Security Patch Release
Summary
Hide ▲
Show ▼
SAP released 21 new and four updated security notes covering NetWeaver and other products, including several critical-severity vulnerabilities that could enable remote code execution, data exposure, and system takeover. The patch release bundles fixes for CVE-2025-42944, CVE-2025-42922, and CVE-2025-42958, plus other high-, medium-, and low-severity issues. SAP says it has no indication of in-the-wild exploitation, but it urges customers to apply the patches as soon as possible.
Related Happenings
Oracle security patch release for CVE-2026-21992
Security Patch Release
H score44
First: 21.03.2026 12:24
Last: 21.03.2026 12:24
Sources 1
About this happening:
Oracle released security updates for CVE-2026-21992, a critical flaw in Identity Manager and Web Services Manager that could enable unauthenticated remote co...
Oracle security patch release for CVE-2026-21992
Security Patch ReleaseAbout this happening: Oracle released security updates for CVE-2026-21992, a critical flaw in Identity Manager and Web Services Manager that could enable unauthenticated remote co...
SAP security patch release for CVE-2019-17571
Security Patch Release
H score42
First: 11.03.2026 14:26
Last: 11.03.2026 14:26
Sources 1
About this happening:
SAP released security updates for two critical flaws in FS-QUO and NetWeaver Enterprise Portal Administration, reducing the risk of arbitrary code execution on...
SAP security patch release for CVE-2019-17571
Security Patch ReleaseAbout this happening: SAP released security updates for two critical flaws in FS-QUO and NetWeaver Enterprise Portal Administration, reducing the risk of arbitrary code execution on...
Patch Tuesday multi-vendor security patch release (multiple vulnerabilities)
Security Patch Release
H score48
First: 11.02.2026 15:28
Last: 11.02.2026 15:28
Sources 1
About this happening:
On Patch Tuesday, software vendors released security updates across OS, cloud, network, and application platforms, closing multiple flaws in widely used products and s...
Patch Tuesday multi-vendor security patch release (multiple vulnerabilities)
Security Patch ReleaseAbout this happening: On Patch Tuesday, software vendors released security updates across OS, cloud, network, and application platforms, closing multiple flaws in widely used products and s...
Trend Micro security patch release for CVE-2025-69258
Security Patch Release
H score39
First: 09.01.2026 12:01
Last: 09.01.2026 12:01
Sources 1
About this happening:
Trend Micro released security updates for Apex Central for Windows to fix CVE-2025-69258, a 9.8 CVSS remote-code-execution flaw that could let an unauthenticat...
Trend Micro security patch release for CVE-2025-69258
Security Patch ReleaseAbout this happening: Trend Micro released security updates for Apex Central for Windows to fix CVE-2025-69258, a 9.8 CVSS remote-code-execution flaw that could let an unauthenticat...
Atlassian security patch release for CVE-2025-66516
Security Patch Release
H score44
First: 15.12.2025 13:00
Last: 15.12.2025 13:00
Sources 1
About this happening:
Atlassian released December 2025 patches for roughly 30 third-party vulnerabilities, reducing exposure across Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible,...
Atlassian security patch release for CVE-2025-66516
Security Patch ReleaseAbout this happening: Atlassian released December 2025 patches for roughly 30 third-party vulnerabilities, reducing exposure across Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible,...
Timeline
-
09.09.2025 16:52 2 articles · 10mo ago
SAP patches critical NetWeaver vulnerabilities
Mitigation Patch UpdateSAP released 21 new and four updated security notes for NetWeaver and other products, including critical CVE-2025-42944 in the RMI-P4 module of AS Java, CVE-2025-42922 in NetWeaver AS Java's Deploy Web Service, and CVE-2025-42958 on NetWeaver running on IBM i-series. The package also updates a March 2023 security note for a critical directory traversal defect in NetWeaver AS ABAP and adds fixes for Business One, Landscape Transformation Replication Server, S/4HANA, and ABAP Platform, with SAP stating there is no indication of in-the-wild exploitation and urging customers to apply the patches as soon as possible.
Show sources
- SAP Patches Critical NetWeaver Vulnerabilities — www.securityweek.com — 09.09.2025 16:52
- SAP Patches Critical NetWeaver (CVSS Up to 10.0) and High-Severity S/4HANA Flaws — thehackernews.com — 10.09.2025 04:03