logo

Ransomware Operators and Chinese APTs Exploiting SAP NetWeaver Vulnerabilities

ID: 602d65b1-64e4-54cb-ae4f-38d52738b905

STIX ID: report--602d65b1-64e4-54cb-ae4f-38d52738b905

Feed Name: Halcyon Blog

Threat Score
90/100

Date Published: 2025-05-15

Date Updated: 2026-04-28

...
...

SAP NetWeaver Visual Composer contains two critical unauthenticated RCE vulnerabilities (CVE-2025-31324 — CVSS 10, and CVE-2025-42999 — CVSS 9.1) that have been actively exploited since January 2025 by Chinese APTs (UNC5221, UNC5174, CL-STA-0048) and ransomware groups (BianLian, RansomEXX) to deploy webshells across critical infrastructure in the UK, US, and Saudi Arabia; SAP released patches on April 24 and May 2025 and organizations are urged to apply them immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.