← All news
Partnership 1 April 2026

SecurityBridge Research Lab discovers critical SAP code injection vulnerability

SecurityBridge Research Lab discovers critical SAP code injection vulnerability

SecurityBridge's research laboratory has identified CVE-2025-42957, a critical S/4HANA code injection vulnerability now confirmed as exploited in the wild. SAP has released an emergency patch. Icon's managed security clients were protected within hours of disclosure through automated SecurityBridge detection rules.