SAP known exploited vulnerabilities
CISA lists 14 SAP CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2025-05-15), and 3 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2025-31324 (NetWeaver): EPSS 99.5%, added 2025-04-29
- CVE-2020-6207 (Solution Manager): EPSS 98.1%, added 2021-11-03
- CVE-2022-22536 (Multiple Products): EPSS 97.9%, added 2022-08-18
- CVE-2017-12637 (NetWeaver): EPSS 95.1%, added 2025-03-19
- CVE-2020-6287 (NetWeaver): EPSS 94.7%, added 2021-11-03
Most affected SAP products
NetWeaver (10), Commerce Cloud (1), Multiple Products (1), Solution Manager (1), Customer Relationship Management (CRM) (1).
All SAP CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2025-42999 | NetWeaver | NetWeaver Deserialization | 2025-05-15 | 2025-06-05 | 13.9% | Yes |
| CVE-2025-31324 | NetWeaver | NetWeaver Unrestricted File Upload | 2025-04-29 | 2025-05-20 | 99.5% | Yes |
| CVE-2017-12637 | NetWeaver | NetWeaver Directory Traversal | 2025-03-19 | 2025-04-09 | 95.1% | – |
| CVE-2019-0344 | Commerce Cloud | Commerce Cloud Deserialization of Untrusted Data | 2024-09-30 | 2024-10-21 | 7.1% | – |
| CVE-2022-22536 | Multiple Products | Multiple Products HTTP Request Smuggling | 2022-08-18 | 2022-09-08 | 97.9% | – |
| CVE-2021-38163 | NetWeaver | NetWeaver Unrestricted File Upload | 2022-06-09 | 2022-06-30 | 36.0% | – |
| CVE-2016-2388 | NetWeaver | NetWeaver Information Disclosure | 2022-06-09 | 2022-06-30 | 52.2% | – |
| CVE-2016-2386 | NetWeaver | NetWeaver SQL Injection | 2022-06-09 | 2022-06-30 | 71.5% | – |
| CVE-2020-6287 | NetWeaver | NetWeaver Missing Authentication for Critical Function | 2021-11-03 | 2022-05-03 | 94.7% | – |
| CVE-2020-6207 | Solution Manager | Solution Manager Missing Authentication for Critical Function | 2021-11-03 | 2022-05-03 | 98.1% | – |
| CVE-2018-2380 | Customer Relationship Management (CRM) | Customer Relationship Management (CRM) Path Traversal | 2021-11-03 | 2022-05-03 | 28.9% | Yes |
| CVE-2016-9563 | NetWeaver | NetWeaver XML External Entity (XXE) | 2021-11-03 | 2022-05-03 | 24.2% | – |
| CVE-2016-3976 | NetWeaver | NetWeaver Directory Traversal | 2021-11-03 | 2022-05-03 | 47.3% | – |
| CVE-2010-5326 | NetWeaver | NetWeaver Remote Code Execution | 2021-11-03 | 2022-05-03 | 17.8% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors