CVE-2025-42999: SAP NetWeaver Deserialization Vulnerability
Critical severity, CVSS 9.1. Actively exploited: in CISA KEV since 2025-05-15. EPSS: 12.7% chance of exploitation in the next 30 days.
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
Affected products
- SAP NetWeaver: version 7.5 only
Published 2025-05-13. Last modified 2026-08-11.