Listen to this Post

Cyberstorm Warning: Major SAP Security Flaw Now Being Actively Exploited
A newly discovered vulnerability in SAP’s NetWeaver Visual Composer is under heavy exploitation by both sophisticated ransomware groups and state-sponsored cyber actors. The issue, known as CVE-2025-31324, carries the maximum severity score of 10.0 and poses a serious threat to enterprise environments running unpatched SAP software. Since its disclosure in late April, multiple security firms have observed coordinated exploitation efforts — with malware, backdoors, and espionage operations all being traced back to this flaw. The risk is no longer hypothetical: it is active and intensifying.
The Breakdown: What’s Happening Behind the Scenes
SAP’s NetWeaver Visual Composer Framework (version 7.50) is vulnerable to an unauthenticated file upload flaw in its Metadata Uploader component. First spotted by ReliaQuest on April 22 and disclosed by SAP two days later, the exploit lets attackers upload malicious binaries to servers — giving them an open door into critical infrastructure.
Since the flaw’s disclosure, Shadowserver Foundation reported more than 400 SAP NetWeaver servers were openly exposed online. Exploitation quickly followed. Onapsis and WatchTowr confirmed real-world attacks, including the deployment of web shells on vulnerable systems. By April 27, Onapsis and Mandiant released an open-source tool to help detect indicators of compromise.
A second related vulnerability, CVE-2025-42999, was announced by SAP on May 13, pushing the urgency for patching even higher. Like the first, this vulnerability also affects NetWeaver Visual Composer and scored a 9.1 in severity.
Evidence now confirms that the threat actors include not only ransomware groups like BianLian and RansomEXX, but also a Chinese state-sponsored entity labeled Chaya_004. According to Forescout’s Federe Labs, the group has deployed Supershell backdoors and Chinese-made pen testing tools using cloud infrastructure from Chinese providers such as Tencent, Huawei, and Alibaba. Their servers used fake Cloudflare certificates and launched attacks from IPs linked to Chinese hosting services.
Further investigation by EclectiIQ identified Chinese cyber units UNC5221, UNC5174, and CL-STA-0048 — all reportedly connected to China’s Ministry of State Security — as being involved.
Meanwhile, ransomware actors like BianLian have exploited the flaw to set up reverse proxies via the rs64.exe tool. ReliaQuest linked this activity to known BianLian infrastructure. Another wave of attacks came via the PipeMagic backdoor, which was tied to RansomEXX and spread through MSBuild abuse.
The campaigns targeting CVE-2025-31324 highlight how high-profile vulnerabilities are quickly leveraged by diverse threat actors. It’s a call to action for any organization running SAP NetWeaver: patch immediately, monitor systems, and stay alert.
What Undercode Say:
This situation is a textbook example of how quickly modern vulnerabilities can escalate into widespread threats when ignored. The SAP NetWeaver CVE-2025-31324 case underscores multiple ongoing issues in cybersecurity — from delayed patching to the increasing sophistication of threat actor collaboration.
The first major red flag is the exposure of over 400 SAP NetWeaver servers to the open internet. Given the criticality of SAP systems — often managing financials, logistics, HR, and procurement — this is not just poor hygiene; it’s an open invitation to compromise. Attackers did not waste time. Within days, real-world exploitation was underway, including the installation of backdoors and malware.
On a strategic level, this is more than opportunistic ransomware. The involvement of Chinese nation-state actors like Chaya_004, UNC5221, and others confirms that this vulnerability is also being weaponized for espionage. This dual-use of the flaw — for both economic and intelligence-gathering purposes — reflects a growing pattern where nation-states and cybercriminals pursue similar entry points but for different end goals.
Technically, the vulnerability is terrifying. The ability to upload executable files without authentication means full system compromise is possible without requiring any credentials. Combine that with poor segmentation in enterprise environments, and the infection can propagate far beyond SAP.
ReliaQuest’s attribution work adds depth to the analysis. The use of MSBuild to deploy PipeMagic and the reuse of certificates between IPs reveals how much reconnaissance and infrastructure alignment goes into these operations. It’s not a smash-and-grab — it’s calculated and persistent.
One of the most disturbing findings is the use of impersonated Cloudflare certificates by the Chinese actors. It’s a reminder that TLS and HTTPS can’t be blindly trusted without certificate validation and anomaly detection tools in place. Threat actors are mimicking trusted providers to bypass security controls.
This vulnerability, coupled with the associated CVE-2025-42999 flaw, suggests a broader security design issue in NetWeaver Visual Composer’s architecture. SAP must invest further in secure-by-design principles, especially as their software powers critical business operations across the globe.
On the defense side, the fact that tools for detection were released relatively quickly is encouraging. But organizations must go beyond detection and enforce strict segmentation, zero-trust models, and automated patching where feasible.
Ultimately, this event reinforces a harsh truth in cybersecurity: even the biggest names in enterprise software are vulnerable — and when the patches come out, the clock starts ticking fast.
Fact Checker Results ✅
The vulnerability CVE-2025-31324 has been confirmed by SAP and received the highest CVSS score: 10.0 🔥
Multiple cybersecurity firms have independently verified active exploitation in the wild 🕵️
Attribution to Chinese threat actors and ransomware groups is supported by threat intel and forensic infrastructure analysis 🌐
Prediction 🔮
With the level of attention this vulnerability has gained from ransomware groups and state-backed entities, we predict that CVE-2025-31324 will remain a top target for at least the next six months. Expect to see more advanced variants of attacks using this exploit, possibly integrating AI-driven malware or polymorphic techniques. Enterprises that delay patching are likely to experience lateral movement within their networks, leading to data breaches or prolonged operational disruptions. As attack kits become more automated, this flaw may soon be exploited by low-skilled actors as well.
References:
Reported By: www.infosecurity-magazine.com
Extra Source Hub:
https://www.discord.com
Wikipedia
Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




