CISA's list that day

9 June 2022

On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in SAP NetWeaver. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2016-2386SQL InjectionSAP NetWeaverPatch this weekEPSS 0.720.72
CVE-2016-2388Information DisclosureSAP NetWeaverPatch this weekEPSS 0.520.52
CVE-2021-38163Unrestricted File UploadSAP NetWeaverPatch soon0.37

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.