Vendor Exploitation Record

SAP (NetWeaver) — Known Exploited Vulnerabilities

14 in CISA KEV · 3 ransomware-linked · as of 2026-08-31
In CISA KEV14 confirmed exploited
Ransomware-linked3 (21% of KEV, per CISA)
First KEV addition2021-11-03
Most recent2025-05-15

How we count

Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to SAP (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.

Exploited SAP vulnerabilities (CISA KEV)

CVEProductVulnerabilityAdded
CVE-2025-42999NetWeaverSAP NetWeaver Deserialization Vulnerability2025-05-15ransomware
CVE-2025-31324NetWeaverSAP NetWeaver Unrestricted File Upload Vulnerability2025-04-29ransomware
CVE-2017-12637NetWeaverSAP NetWeaver Directory Traversal Vulnerability2025-03-19
CVE-2019-0344Commerce CloudSAP Commerce Cloud Deserialization of Untrusted Data Vulnerability2024-09-30
CVE-2022-22536Multiple ProductsSAP Multiple Products HTTP Request Smuggling Vulnerability2022-08-18
CVE-2021-38163NetWeaverSAP NetWeaver Unrestricted File Upload Vulnerability2022-06-09
CVE-2016-2386NetWeaverSAP NetWeaver SQL Injection Vulnerability2022-06-09
CVE-2016-2388NetWeaverSAP NetWeaver Information Disclosure Vulnerability2022-06-09
CVE-2018-2380Customer Relationship Management (CRM)SAP Customer Relationship Management (CRM) Path Traversal Vulnerability2021-11-03ransomware
CVE-2010-5326NetWeaverSAP NetWeaver Remote Code Execution Vulnerability2021-11-03
CVE-2016-9563NetWeaverSAP NetWeaver XML External Entity (XXE) Vulnerability2021-11-03
CVE-2020-6287NetWeaverSAP NetWeaver Missing Authentication for Critical Function Vulnerability2021-11-03
CVE-2020-6207Solution ManagerSAP Solution Manager Missing Authentication for Critical Function Vulnerability2021-11-03
CVE-2016-3976NetWeaverSAP NetWeaver Directory Traversal Vulnerability2021-11-03

← All vendors by exploited-vulnerability count

🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.

Track newly exploited vulnerabilities

Free daily briefing on CVEs added to CISA KEV and exploited in the wild.