CVE-2025-42999
SAP NetWeaver Deserialization Vulnerability
9.1
CVSS 3.1
13.9 %
EPSS (current)
2025-05-15
KEV addition
Yes
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: SAP / NetWeaver
Published: 2025-05-13 · Due (CISA): 2025-06-05
CWE: CWE-502 · EU list: no
Exploit references (metadata only)
No public exploit references recorded.