Ransomware Operators and Chinese APTs Exploiting SAP NetWeaver Vulnerabilities
ID: 602d65b1-64e4-54cb-ae4f-38d52738b905
STIX ID: report--602d65b1-64e4-54cb-ae4f-38d52738b905
Feed Name: Halcyon Blog
Threat Score
SAP NetWeaver Visual Composer contains two critical unauthenticated RCE vulnerabilities (CVE-2025-31324 — CVSS 10, and CVE-2025-42999 — CVSS 9.1) that have been actively exploited since January 2025 by Chinese APTs (UNC5221, UNC5174, CL-STA-0048) and ransomware groups (BianLian, RansomEXX) to deploy webshells across critical infrastructure in the UK, US, and Saudi Arabia; SAP released patches on April 24 and May 2025 and organizations are urged to apply them immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
