SAP NetWeaver known exploited vulnerabilities, ranked
CISA lists 10 SAP NetWeaver CVEs as exploited in the wild. 0 were added in the last 12 months and 2 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.
Patch these first
- CVE-2025-31324: EPSS 99.49%, used in ransomware, added 2025-04-29
- CVE-2017-12637: EPSS 95.1%, added 2025-03-19
- CVE-2020-6287: EPSS 94.7%, added 2021-11-03
- CVE-2016-2386: EPSS 71.5%, added 2022-06-09
- CVE-2016-2388: EPSS 52.2%, added 2022-06-09
All 10 SAP NetWeaver CVEs in CISA KEV, by EPSS
| # | CVE | Flaw | EPSS | Ransomware | Added | Federal due |
|---|---|---|---|---|---|---|
| 1 | CVE-2025-31324 | NetWeaver Unrestricted File Upload | 99.49% | Yes | 2025-04-29 | 2025-05-20 |
| 2 | CVE-2017-12637 | NetWeaver Directory Traversal | 95.1% | – | 2025-03-19 | 2025-04-09 |
| 3 | CVE-2020-6287 | NetWeaver Missing Authentication for Critical Function | 94.7% | – | 2021-11-03 | 2022-05-03 |
| 4 | CVE-2016-2386 | NetWeaver SQL Injection | 71.5% | – | 2022-06-09 | 2022-06-30 |
| 5 | CVE-2016-2388 | NetWeaver Information Disclosure | 52.2% | – | 2022-06-09 | 2022-06-30 |
| 6 | CVE-2016-3976 | NetWeaver Directory Traversal | 47.3% | – | 2021-11-03 | 2022-05-03 |
| 7 | CVE-2021-38163 | NetWeaver Unrestricted File Upload | 36.0% | – | 2022-06-09 | 2022-06-30 |
| 8 | CVE-2016-9563 | NetWeaver XML External Entity (XXE) | 24.2% | – | 2021-11-03 | 2022-05-03 |
| 9 | CVE-2010-5326 | NetWeaver Remote Code Execution | 17.8% | – | 2021-11-03 | 2022-05-03 |
| 10 | CVE-2025-42999 | NetWeaver Deserialization | 13.9% | Yes | 2025-05-15 | 2025-06-05 |
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint.
Sources: CISA KEV, FIRST EPSS.
More: all SAP KEV CVEs · free KEV badge for SAP · all vendors