<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://exploit-radar.com/en/flux/marques/sap.xml</id>
  <title>Exploit Radar: exploited SAP vulnerabilities</title>
  <subtitle>The latest additions to CISA’s catalog of exploited vulnerabilities for SAP products.</subtitle>
  <link rel="self" type="application/atom+xml" href="https://exploit-radar.com/en/flux/marques/sap.xml"/>
  <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/marques/sap/"/>
  <updated>2025-05-15T00:00:00Z</updated>
  <author><name>Exploit Radar</name></author>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-42999/</id>
    <title>CVE-2025-42999 — SAP NetWeaver</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-42999/"/>
    <updated>2025-05-15T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SAP; if none are available, stop using the product. For cloud services, follow the guidance from SAP. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on May 15, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-31324/</id>
    <title>CVE-2025-31324 — SAP NetWeaver</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-31324/"/>
    <updated>2025-04-29T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SAP; if none are available, stop using the product. For cloud services, follow the guidance from SAP. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on April 29, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2017-12637/</id>
    <title>CVE-2017-12637 — SAP NetWeaver</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2017-12637/"/>
    <updated>2025-03-19T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SAP; if none are available, stop using the product. For cloud services, follow the guidance from SAP. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 19, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2019-0344/</id>
    <title>CVE-2019-0344 — SAP Commerce Cloud (Hybris)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2019-0344/"/>
    <updated>2024-09-30T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SAP; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on September 30, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-22536/</id>
    <title>CVE-2022-22536 — SAP NetWeaver</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-22536/"/>
    <updated>2022-08-18T00:00:00Z</updated>
    <summary type="text">Apply the security update from SAP. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on August 18, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2016-2386/</id>
    <title>CVE-2016-2386 — SAP NetWeaver</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2016-2386/"/>
    <updated>2022-06-09T00:00:00Z</updated>
    <summary type="text">Apply the security update from SAP. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on June 9, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-38163/</id>
    <title>CVE-2021-38163 — SAP NetWeaver</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-38163/"/>
    <updated>2022-06-09T00:00:00Z</updated>
    <summary type="text">Apply the security update from SAP. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on June 9, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2016-2388/</id>
    <title>CVE-2016-2388 — SAP NetWeaver</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2016-2388/"/>
    <updated>2022-06-09T00:00:00Z</updated>
    <summary type="text">Apply the security update from SAP. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on June 9, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2010-5326/</id>
    <title>CVE-2010-5326 — SAP NetWeaver</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2010-5326/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from SAP. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-6287/</id>
    <title>CVE-2020-6287 — SAP NetWeaver</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-6287/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from SAP. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-6207/</id>
    <title>CVE-2020-6207 — SAP Solution Manager</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-6207/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from SAP. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2016-3976/</id>
    <title>CVE-2016-3976 — SAP NetWeaver</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2016-3976/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from SAP. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2018-2380/</id>
    <title>CVE-2018-2380 — SAP CRM</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2018-2380/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from SAP. CISA deadline: 181 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2016-9563/</id>
    <title>CVE-2016-9563 — SAP NetWeaver</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2016-9563/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from SAP. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
</feed>
