CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2025-31324: SAP NetWeaver Vulnerability Exploited by Multiple Threat Actors

August 15, 2026

CVE-2025-31324 is a critical vulnerability in SAP NetWeaver that has been weaponized by China-nexus espionage clusters such as UNC5221, UNC5174, and CL-STA-0048, as well as cybercrime groups like BianLian and RansomExx. In April 2025, unknown actors exploited it to deploy the Auto-Color backdoor against a U.S. chemicals company.