CVE-2025-31324: SAP NetWeaver Vulnerability Exploited by Multiple Threat Actors
August 15, 2026
CVE-2025-31324 is a critical vulnerability in SAP NetWeaver that has been weaponized by China-nexus espionage clusters such as UNC5221, UNC5174, and CL-STA-0048, as well as cybercrime groups like BianLian and RansomExx. In April 2025, unknown actors exploited it to deploy the Auto-Color backdoor against a U.S. chemicals company.