Tuesday, 19 August

Tuesday, 19 August2025

New SAP NetWeaver Zero-Day RCE Exploit Uses ABAP Backdoors & Dynamic Payloads

New SAP NetWeaver Zero-Day RCE Exploit Uses ABAP Backdoors & Dynamic Payloads
A sophisticated zero-day exploit targeting SAP NetWeavers ICM component enables unauthenticated attackers to achieve remote code execution (RCE) and install stealthy backdoors. The exploit sends crafted HTTP requests to the metadatauploader endpoint, triggering ABAP code injection and buffer overflow. Attackers insert hidden ABAP programs for persistent access and data theft via SQL manipulation. The script masks itself within legitimate SAP logicmaking detection extremely difficult.

Subscribe To Our Newsletter.

Full Name
Email