Skip to content
eastbaycyber

SAP: CISA KEV History

Every SAP vulnerability in the CISA Known Exploited Vulnerabilities catalog: confirmed in-the-wild exploitation, addition timeline, and ransomware linkage. Rebuilt automatically on every site deploy.

Snapshot: 2026-09-08 · Source: CISA KEV Catalog · Full KEV dashboard

KEV entries
14
Added, last 12 months
0
Ransomware-linked
3
Latest addition
2025-05-15

SAP KEV additions per month, last 24 months

2024-10: 0 added24/102024-11: 0 added2024-12: 0 added2025-01: 0 added25/012025-02: 0 added2025-03: 1 added12025-04: 1 added125/042025-05: 1 added12025-06: 0 added2025-07: 0 added25/072025-08: 0 added2025-09: 0 added2025-10: 0 added25/102025-11: 0 added2025-12: 0 added2026-01: 0 added26/012026-02: 0 added2026-03: 0 added2026-04: 0 added26/042026-05: 0 added2026-06: 0 added2026-07: 0 added26/072026-08: 0 added2026-09: 0 added

Most-listed products: NetWeaver, Commerce Cloud, Multiple Products, Customer Relationship Management (CRM), Solution Manager.

Latest 14 of 14 SAP KEV entries

CVEVulnerabilityAddedRansomware
CVE-2025-42999SAP NetWeaver Deserialization Vulnerability2025-05-15Yes
CVE-2025-31324SAP NetWeaver Unrestricted File Upload Vulnerability2025-04-29Yes
CVE-2017-12637SAP NetWeaver Directory Traversal Vulnerability2025-03-19No
CVE-2019-0344SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability2024-09-30No
CVE-2022-22536SAP Multiple Products HTTP Request Smuggling Vulnerability2022-08-18No
CVE-2021-38163SAP NetWeaver Unrestricted File Upload Vulnerability2022-06-09No
CVE-2016-2386SAP NetWeaver SQL Injection Vulnerability2022-06-09No
CVE-2016-2388SAP NetWeaver Information Disclosure Vulnerability2022-06-09No
CVE-2018-2380SAP Customer Relationship Management (CRM) Path Traversal Vulnerability2021-11-03Yes
CVE-2010-5326SAP NetWeaver Remote Code Execution Vulnerability2021-11-03No
CVE-2016-9563SAP NetWeaver XML External Entity (XXE) Vulnerability2021-11-03No
CVE-2020-6287SAP NetWeaver Missing Authentication for Critical Function Vulnerability2021-11-03No
CVE-2020-6207SAP Solution Manager Missing Authentication for Critical Function Vulnerability2021-11-03No
CVE-2016-3976SAP NetWeaver Directory Traversal Vulnerability2021-11-03No

CVE links go to our explainer when one exists, otherwise to the NVD record.

Data: official CISA KEV catalog, fetched at build time. Figures may be reused with attribution to East Bay Cyber and CISA. See also the KEV Velocity Dashboard and all tracked vendors.