CyberMax
Home › Exploited CVEs › SAP

SAP NetWeaver known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 10 SAP NetWeaver CVEs as exploited in the wild. 0 were added in the last 12 months and 2 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 10 SAP NetWeaver CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2025-31324NetWeaver Unrestricted File Upload99.49%Yes2025-04-292025-05-20
2CVE-2017-12637NetWeaver Directory Traversal95.1%–2025-03-192025-04-09
3CVE-2020-6287NetWeaver Missing Authentication for Critical Function94.7%–2021-11-032022-05-03
4CVE-2016-2386NetWeaver SQL Injection71.5%–2022-06-092022-06-30
5CVE-2016-2388NetWeaver Information Disclosure52.2%–2022-06-092022-06-30
6CVE-2016-3976NetWeaver Directory Traversal47.3%–2021-11-032022-05-03
7CVE-2021-38163NetWeaver Unrestricted File Upload36.0%–2022-06-092022-06-30
8CVE-2016-9563NetWeaver XML External Entity (XXE)24.2%–2021-11-032022-05-03
9CVE-2010-5326NetWeaver Remote Code Execution17.8%–2021-11-032022-05-03
10CVE-2025-42999NetWeaver Deserialization13.9%Yes2025-05-152025-06-05
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all SAP KEV CVEs · free KEV badge for SAP · all vendors