Microsoft, Adobe, SAP deliver critical fixes for September 2025 Patch Tuesday
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-31324 | Unauthenticated File Upload RCE in SAP NetWeaver Visual Composer CVE-2025-31324 is a critical (CVSS 9.8) unrestricted file upload flaw (CWE-434) in the Visual Composer Metadata Uploader component of SAP NetWeaver, which lacks proper authorization. An unauthenticated attacker can send crafted upload requests over the network to the Metadata Uploader endpoint and plant malicious executable binaries, such as webshells, on the host. Executing the uploaded files yields remote code execution with full impact on confidentiality, integrity, and availability, enabling system compromise, lateral movement, and ransomware deployment. Any organization running the affected SAP NetWeaver component is at risk, with the greatest exposure for instances reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2025-04-29, a public PoC exists, and researchers and media report active attacks, including by Chinese-linked actors deploying Golang-based implants on Linux systems and known ransomware use, often chained with CVE-2025-42999. Do: Apply SAP's patch for CVE-2025-31324 (released in the April 2025 security updates) and follow the vendor mitigation instructions per CISA KEV/BOD 22-01 requirements. As interim mitigation, restrict or disable the Visual Composer Metadata Uploader endpoint and ensure it is not reachable from the internet; also patch the related CVE-2025-42999 since the flaws are being chained. Check affected hosts for uploaded webshells, Golang-based implants, and signs of ransomware activity. | 9.8 | 100% | KEV ransomware PoC |
| largetens of thousands of enterprise deployments worldwide, with several thousand instances directly internet-exposed | |
| CVE-2025-42922 | SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. This file when executed can lead to a full compromise of confidentiality, integrity and availability of the system. NVD description · AI analysis pending | 9.9 | <1% | — | — | ||
| CVE-2025-42944 | Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects could lead to arbitrary OS command execution, posing a high impact to the application's confidentiality, integrity, and availability. NVD description · AI analysis pending | 10.0 | 3% | — | — | ||
| CVE-2025-42958 | Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modif Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access administrative or privileged functionalities. This results in a high impact on the confidentiality, integrity, and availability of the application. NVD description · AI analysis pending | 9.1 | <1% | — | — | ||
| CVE-2025-54236 | Unauthenticated Session Takeover in Adobe Commerce and Magento (SessionReaper) Adobe Commerce and Magento Open Source contain an improper input validation flaw (CWE-20), widely tracked as 'SessionReaper', that lets a remote, unauthenticated attacker take over user sessions. The flaw is exploitable over the network with no privileges and no user interaction (CVSS 3.1 9.1, critical). A successful attacker hijacks legitimate customer or admin sessions, yielding high confidentiality and integrity impact; a public writeup additionally describes unauthenticated exploitation potentially reaching code execution. Anyone running Adobe Commerce (including Commerce B2B) or Magento Open Source on the affected 2.4.x releases is exposed. Exploitation is confirmed in the wild: CISA added the flaw to its KEV catalog on 2025-10-24, reporting headlines cite over 250 observed attacks, EPSS is 94.5%, and roughly 3 in 5 stores were reported as still unpatched. Do: Immediately upgrade every affected 2.4.x line to a release newer than 2.4.9-alpha2/2.4.8-p2/2.4.7-p7/2.4.6-p12/2.4.5-p14/2.4.4-p15 per Adobe's security advisory. Because the flaw is on CISA's KEV list, federal agencies must apply the vendor's mitigations (or BOD 22-01 cloud guidance) or discontinue use; other defenders should prioritize patching given 250+ observed attacks and 94.5% EPSS. Until patched, watch for indicators of session takeover — unexpected customer or admin sessions, unfamiliar admin accounts, and anomalous session activity — and review Adobe's advisory for interim mitigations. | 9.1 | 95% | KEV PoC |
| mass≈100,000+ internet-facing Adobe Commerce/Magento storefronts (order of magnitude 10^5) | |
| CVE-2025-54261 | Critical Path Traversal Leading to RCE in Adobe ColdFusion 2025/2023/2021 CVE-2025-54261 is an Improper Limitation of a Pathname to a Restricted Directory (path traversal, CWE-22) flaw in Adobe ColdFusion that allows an attacker to escape a restricted directory and achieve arbitrary code execution. It is remotely exploitable over the network with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), but only on servers where certain optional configurations are enabled. Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability, and the changed-scope rating indicates the attacker's impact can cross the vulnerable component's security boundary (e.g., reach other system resources). Affected deployments are ColdFusion 2025, 2023, and 2021 servers on update levels 2025.3, 2023.15, and 2021.21 or earlier that have the relevant optional configuration active. There is no public proof-of-concept and the flaw is not yet in CISA's KEV, but the ~21% EPSS probability (97th percentile) signals elevated risk of exploitation in the next 30 days, so patching should be treated as urgent. Do: Upgrade every ColdFusion 2025, 2023, and 2021 installation to the latest update release beyond 2025.3 / 2023.15 / 2021.21 per Adobe's September 2025 security bulletin, prioritizing internet-facing servers given the elevated EPSS. Inventory deployments for the optional configurations implicated by the advisory and, until patched, restrict network access to ColdFusion endpoints (e.g., at the firewall/reverse-proxy layer). Monitor Adobe's advisory and CISA KEV for confirmation of active exploitation. | 10.0 | 21% |
| large≈10,000–50,000 internet-exposed ColdFusion servers (public internet-wide scans; total installed base unpublished) | ||
| CVE-2025-55234 | SMB Relay Elevation of Privilege in Microsoft Windows SMB Server CVE-2025-55234 is an improper authentication flaw (CWE-287) in the Microsoft SMB Server that leaves systems susceptible to credential relay attacks when SMB signing and Extended Protection for Authentication (EPA) are not enforced. It is configuration-dependent: an attacker who can induce an authenticated SMB connection, for example by tricking a user or machine into connecting to attacker-controlled resources, can relay the credentials to another host and authenticate as that user. Successful relaying grants the attacker the privileges of the relayed user, up to elevation of privilege on target systems, with high impact on confidentiality, integrity and availability. Affected systems span Windows 10 (1507 through 22H2), Windows 11 (22H2 through 24H2), and Windows Server 2008, 2012, 2016 and 2019, although only environments without SMB signing/EPA hardening are practically exploitable. As of the September 2025 Patch Tuesday release there is no known in-the-wild exploitation or public proof of concept, but EPSS assigns a 20.1% probability of exploitation within the next 30 days (97th percentile). Do: Install the September 2025 (or later) Microsoft security updates, which add SMB Server Hardening audit capabilities, and use the new audit events to identify clients, servers or legacy software that would break if SMB signing and EPA are enforced. After remediating incompatibilities, enable SMB Server signing and Extended Protection for Authentication on SMB servers to close the relay exposure, prioritizing domain controllers and file servers. Note that systems already enforcing both signing and EPA are not practically exposed. | 9.8 group max | 20% |
| masshundreds of millions of Windows 10/11 devices plus millions of Windows Server instances are potentially exposed, though only those lacking SMB signing/EPA… | ||
| CVE-2025-55232 | Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network. Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 9.8 | 2% |
| — |
Full article1,035 words · extracted from helpnetsecurity.com · click to collapse
On September 2025 Patch Tuesday, Microsoft has released patches for 80+ vulnerabilities in its various software products, but the good news is that none of them are actively exploited.

Among the critical and important vulnerabilities patched by Microsoft this time around are:
CVE-2025-54918, a remotely exploitable Windows NTLM elevation of privilege vulnerability. “The attack complexity is Low because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component,” Microsoft noted.
Satnam Narang, senior staff research engineer at Tenable, has singled out CVE-2025-54916 – a stack-based buffer overflow in Windows NTFS that may lead to remote code execution – as worthy of a quick patch.
In March 2025, Microsoft fixed three NTFS vulnerabilities that were exploited in the wild as zero-days. “While this one does not appear to have been exploited, it is still certainly worth keeping an eye on since NTFS is the primary file system used by Windows,” he told Help Net Security.
Kev Breen, Senior Director Threat Research at Immersive, noted that while the title of this CVE says ‘Remote Code Execution,’ this exploit is not remotely exploitable over the network, but instead needs an attacker to either have the ability to run code on the host or to convince a user to run a file that would trigger the exploit.
“This is commonly seen in social engineering attacks, where they send the user a file to open as an attachment or a link to a file to download and run,” he added.
CVE-2025-55232, a vulnerability in the Microsoft High Performance Compute (HPC) Pack, is used to turn a set of Windows Server machines into a coordinated cluster.
The flaw could allow remote, unauthenticated attackers to achieve code execution on affected systems without any user interaction, which – according to Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative – makes it potentially wormable between systems with the HPC pack installed.
Users are advised to update/migrate to HPC Pack 2019 Update 3 (Build 6.3.8328) and apply the “quick fix” (Build 6.3.8352). If they can’t, they should mitigate the risk of exploitation by running HPC Pack clusters “in a trusted network secured by firewall rules especially for the TCP port 5999.”
Jacob Ashdown, Cyber Security Engineer at Immersive, advises organizations with remote employees or employees who travel frequently to close CVE-2025-54912, sooner rather than later.
CVE-2025-54912 affects BitLocker, the disk encryption tool built into the Windows OS, and could allow attackers to bypass BitLocker protections through physical access to a device.
“This flaw allows an attacker to gain unauthorized access to encrypted data on the system drive with no user interaction or prior privileges required. Microsoft notes the attack complexity is low, although no public exploit code currently exists,” he commented.
“If exploited, this flaw could expose sensitive files, credentials, or allow tampering with system integrity. This poses a particular risk for organizations where devices may be lost or stolen, as attackers with hands-on access could potentially bypass encryption and extract sensitive data.”
It’s also good to mention that two of the flaws fixed this Tuesday were previously disclosed, and the security bulletin for the latter – CVE-2025-55234, an elevation of privilege flaw in Windows SMB Server – notes that the solution for it is hardening SMB Server against relay attacks.
In effect, the “fix” is the audit capabilities Microsoft has released in the September 2025 security updates for Windows and Windows servers, which admins should use to check whether they those hardening measures are in place and, if they are not, to implement them.
Adobe fixes
Adobe has released fixes for 22 CVE-numbered vulnerabilities in Acrobat and Reader, After Effects, Premiere Pro, Substance 3D Viewer, Experience Manager, Dreamweaver, Adobe 3D Substance Modeler, ColdFusion, and Commerce (and Magento Open Source).
None of the fixed vulnerabilities are under active exploitation, but Adobe deems the ColdFusion and Commerce / Magento updates more important to implement quickly than the others.
ColdFusion users received a fix for a critical path traversal flaw (CVE-2025-54261) that could lead to to arbitrary file system write and a recommendation to use the latest MySQL java connector (“for security reasons”).
Adobe Commerce (formerly Magento Commerce) and Magento Open Source users should implement a hotfix for CVE-2025-54236, an improper input validation vulnerability that may allow attackers to bypass a security feature.
Security company Sansec says that the release of the fix was privately announced to selected Commerce customers last week.
So far, neither Adobe or Sansec have seen evidence of the vulnerability being exploited by attackers, but that could happen sooner than expected, since the Adobe patch was accidentally leaked last week.
“The bug, dubbed SessionReaper (…), allows customer account takeover and unauthenticated remote code execution under certain conditions. Sansec was able to simulate the attack and so may less benign parties,” the Sansec Forensics Team warned.
SAP fixes
The German software corporation, which is the world’s largest vendor of enterprise resource planning (ERP) software, also releases patches for its various offerings on the second Tuesday of every month.
On this month’s “SAP Security Patch Day”, the company has fixed a bucketload of flaws in its various offerings, including several critical vulnerabilities in SAP NetWeaver (the integration platform that lets SAP and non-SAP systems work together smoothly):
- CVE-2025-42944, which may allow remote, unauthenticated attackers to execute OS commands on vulnerable systems by submitting a malicious payload to an open port
- CVE-2025-42922, which may allow an attacker authenticated as a non-administrative user to exploit the flaw to upload an arbitrary (malicious) file and execute it.
CVE-2025-42958, stemming from a missing authentication check, may allow high privileged unauthorized users to read, modify, or delete sensitive information, and access administrative or privileged functionalities.
While there’s no mention of any of these being leveraged by attackers, SAP Netweaver is obviously an attractive target. A SAP Netweaver vulnerability (CVE-2025-31324) has recently been exploited in zero-day attacks by suspected initial access broker, and an exploit chaining it and another previously exploited flaw has recently been publicly released.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/09/10/microsoft-adobe-sap-deliver-critical-fixes-for-september-2025-patch-tuesday/