Skip to main content

Recently Exploited SAP CVEs

Affected Products

5 products
ProductCVEsKEVLatest
NetWeaver10102025-05-15
Commerce Cloud112024-09-30
Customer Relationship Management (CRM)112021-11-03
Multiple Products112022-08-18
Solution Manager112021-11-03

Security Advisories

SAP Security Notes & News (monthly Security Patch Day)
https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html

Weakness Types

All SAP CVEs

14 records
CVETitleVendorCVSSEPSSKEVPublished
CVE-2025-42999
Insecure Deserialization in SAP NetWeaver (Visual Composer development server)
SAP_SE9.113.9%KEV2025-05-13
CVE-2025-31324
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
SAP_SE10.099.5%KEV2025-04-24
CVE-2017-12637
SAP NetWeaver Directory Traversal Vulnerability
-7.595.1%KEV2017-08-07
CVE-2019-0344
SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
SAP SE9.87.1%KEV2019-08-14
CVE-2022-22536
SAP Multiple Products HTTP Request Smuggling Vulnerability
SAP SE9.897.9%KEV2022-02-09
CVE-2016-2386
SAP NetWeaver SQL Injection Vulnerability
-9.871.5%KEV2016-02-16
CVE-2016-2388
SAP NetWeaver Information Disclosure Vulnerability
-5.352.2%KEV2016-02-16
CVE-2021-38163
SAP NetWeaver Unrestricted File Upload Vulnerability
SAP SE9.936.9%KEV2021-09-14
CVE-2020-6207
SAP Solution Manager Missing Authentication for Critical Function Vulnerability
SAP SE10.098.1%KEV2020-03-10
CVE-2020-6287
SAP NetWeaver Missing Authentication for Critical Function Vulnerability
SAP SE10.094.7%KEV2020-07-14
CVE-2016-3976
SAP NetWeaver Directory Traversal Vulnerability
-7.547.3%KEV2016-04-07
CVE-2018-2380
SAP Customer Relationship Management (CRM) Path Traversal Vulnerability
SAP SE6.628.9%KEV2018-03-01
CVE-2016-9563
SAP NetWeaver XML External Entity (XXE) Vulnerability
-6.524.2%KEV2016-11-23
CVE-2010-5326
SAP NetWeaver Remote Code Execution Vulnerability
-10.017.8%KEV2016-05-13

Frequently Asked Questions

How many SAP vulnerabilities are actively exploited?→

14 SAP CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2025-05-15.

Which SAP vulnerabilities are used in ransomware attacks?→

CISA marks 3 SAP KEV entries as known to be used in ransomware campaigns, including CVE-2025-42999, CVE-2025-31324, CVE-2018-2380.

Which SAP products have the most exploited vulnerabilities?→
  • +NetWeaver: 10 CVEs (10 in KEV)
  • +Commerce Cloud: 1 CVE (1 in KEV)
  • +Customer Relationship Management (CRM): 1 CVE (1 in KEV)
  • +Multiple Products: 1 CVE (1 in KEV)
  • +Solution Manager: 1 CVE (1 in KEV)
Where does SAP publish security advisories?→

SAP publishes security advisories at https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html. Check the vendor advisory for fixed versions and workarounds before applying updates.

Sources

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by SAP, MITRE, CISA, or FIRST.