
SAP ERP Systems Face First Zero-Day Exploit as Security Expert Reveals 100% Penetration Success Rate
Wael Feguirier, a cybersecurity engineer at KPMG specializing in offensive security and SAP cybersecurity, discusses the evolving security landscape of SAP ERP systems. SAP is an enterprise resource planning system that manages business processes like manufacturing, supply chain, and accounting through a suite of interconnected applications. Between April and August 2025, the first zero-day vulnerability in SAP was identified being actively exploited in the wild, marking a paradigm shift from previous research-only vulnerability discoveries. The exploitation involved two CVEs that allowed remote system access without authentication. SAP environments use proprietary protocols like RFC, proprietary PKI systems, and the ABAP programming language, running on a common application server foundation called NetWeaver (now ABAP Platform). Feguirier reports a 100% success rate in achieving SAP administrator privileges across all penetration tests conducted, primarily due to unaudited configurations and lack of proper monitoring. Key security recommendations include robust authorization management beyond standard segregation of duties, network segmentation, configuration hardening of profile parameters, and comprehensive logging for security operations centers. An open-source tool called SAP Exec, modeled after NetExec, is scheduled for release around September-October to facilitate security testing of SAP systems.