SAP has released critical security patches addressing a maximum-severity vulnerability in NetWeaver AS Java that enables arbitrary command execution. The flaw, scored 10/10, affects systems through the RMI-P4 module and could compromise confidentiality, integrity, and availability. Organizations are urged to apply patches immediately to prevent potential exploitation. 
Maximum-Severity SAP Vulnerability Threatens Enterprise Systems
Software giant SAP has released critical security hardening for a maximum-severity vulnerability that grants threat actors arbitrary command execution capabilities on compromised endpoints, according to recent security advisories. The vulnerability, tracked as CVE-2025-42944, affects SAP NetWeaver AS Java and has received a perfect 10/10 severity score, indicating the highest level of risk to organizational systems.