Product of SAP

NetWeaver

As of , 10 SAP NetWeaver vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2020-6287.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2020-6287Missing Authentication for Critical FunctionSAP NetWeaverPatch this weekMetasploit module; EPSS 0.950.95
2CVE-2025-31324Unrestricted File UploadSAP NetWeaverPatch this weekRansomware use; EPSS 0.990.99
3CVE-2017-12637Directory TraversalSAP NetWeaverPatch this weekEPSS 0.950.95
4CVE-2016-2386SQL InjectionSAP NetWeaverPatch this weekEPSS 0.720.72
5CVE-2016-2388Information DisclosureSAP NetWeaverPatch this weekEPSS 0.520.52
6CVE-2025-42999DeserializationSAP NetWeaverPatch this weekRansomware use0.14
7CVE-2021-38163Unrestricted File UploadSAP NetWeaverPatch soon0.37
8CVE-2016-3976Directory TraversalSAP NetWeaverPatch soon0.47
9CVE-2010-5326Remote Code ExecutionSAP NetWeaverPatch soon0.18
10CVE-2016-9563XML External Entity (XXE)SAP NetWeaverPatch soon0.24

Added each year

12342021: 4420212022: 3320222023: nonenone20232024: nonenone20242025: 3320252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20214
20223
2023none
2024none
20253
2026none

Used in ransomware

Changes CISA made to these entries

  1. CVE-2025-42999 SAP NetWeaverRansomware use: Unknown to Known.
  2. CVE-2025-31324 SAP NetWeaverRansomware use: Unknown to Known.

Every change we recorded