CyberMax
Home › Exploited CVEs

SAP known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 14 SAP CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2025-05-15), and 3 are known to be used in ransomware campaigns.

SAP CVEs added to CISA KEV per year
2021: 6202162022: 4202242024: 1202412025: 320253

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected SAP products

NetWeaver (10), Commerce Cloud (1), Multiple Products (1), Solution Manager (1), Customer Relationship Management (CRM) (1).

All SAP CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2025-42999NetWeaverNetWeaver Deserialization2025-05-152025-06-0513.9%Yes
CVE-2025-31324NetWeaverNetWeaver Unrestricted File Upload2025-04-292025-05-2099.5%Yes
CVE-2017-12637NetWeaverNetWeaver Directory Traversal2025-03-192025-04-0995.1%–
CVE-2019-0344Commerce CloudCommerce Cloud Deserialization of Untrusted Data2024-09-302024-10-217.1%–
CVE-2022-22536Multiple ProductsMultiple Products HTTP Request Smuggling2022-08-182022-09-0897.9%–
CVE-2021-38163NetWeaverNetWeaver Unrestricted File Upload2022-06-092022-06-3036.0%–
CVE-2016-2388NetWeaverNetWeaver Information Disclosure2022-06-092022-06-3052.2%–
CVE-2016-2386NetWeaverNetWeaver SQL Injection2022-06-092022-06-3071.5%–
CVE-2020-6287NetWeaverNetWeaver Missing Authentication for Critical Function2021-11-032022-05-0394.7%–
CVE-2020-6207Solution ManagerSolution Manager Missing Authentication for Critical Function2021-11-032022-05-0398.1%–
CVE-2018-2380Customer Relationship Management (CRM)Customer Relationship Management (CRM) Path Traversal2021-11-032022-05-0328.9%Yes
CVE-2016-9563NetWeaverNetWeaver XML External Entity (XXE)2021-11-032022-05-0324.2%–
CVE-2016-3976NetWeaverNetWeaver Directory Traversal2021-11-032022-05-0347.3%–
CVE-2010-5326NetWeaverNetWeaver Remote Code Execution2021-11-032022-05-0317.8%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors