How we count
Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to SAP (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.
Exploited SAP vulnerabilities (CISA KEV)
| CVE | Product | Vulnerability | Added | |
|---|---|---|---|---|
| CVE-2025-42999 | NetWeaver | SAP NetWeaver Deserialization Vulnerability | 2025-05-15 | ransomware |
| CVE-2025-31324 | NetWeaver | SAP NetWeaver Unrestricted File Upload Vulnerability | 2025-04-29 | ransomware |
| CVE-2017-12637 | NetWeaver | SAP NetWeaver Directory Traversal Vulnerability | 2025-03-19 | |
| CVE-2019-0344 | Commerce Cloud | SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability | 2024-09-30 | |
| CVE-2022-22536 | Multiple Products | SAP Multiple Products HTTP Request Smuggling Vulnerability | 2022-08-18 | |
| CVE-2021-38163 | NetWeaver | SAP NetWeaver Unrestricted File Upload Vulnerability | 2022-06-09 | |
| CVE-2016-2386 | NetWeaver | SAP NetWeaver SQL Injection Vulnerability | 2022-06-09 | |
| CVE-2016-2388 | NetWeaver | SAP NetWeaver Information Disclosure Vulnerability | 2022-06-09 | |
| CVE-2018-2380 | Customer Relationship Management (CRM) | SAP Customer Relationship Management (CRM) Path Traversal Vulnerability | 2021-11-03 | ransomware |
| CVE-2010-5326 | NetWeaver | SAP NetWeaver Remote Code Execution Vulnerability | 2021-11-03 | |
| CVE-2016-9563 | NetWeaver | SAP NetWeaver XML External Entity (XXE) Vulnerability | 2021-11-03 | |
| CVE-2020-6287 | NetWeaver | SAP NetWeaver Missing Authentication for Critical Function Vulnerability | 2021-11-03 | |
| CVE-2020-6207 | Solution Manager | SAP Solution Manager Missing Authentication for Critical Function Vulnerability | 2021-11-03 | |
| CVE-2016-3976 | NetWeaver | SAP NetWeaver Directory Traversal Vulnerability | 2021-11-03 |
← All vendors by exploited-vulnerability count
🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.