We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

×

Yikes, there is work to do!
This time we found critical correction advisiories. We count 146 and the highest CVSS score is 10.0.

 

Severity
SAP© Security advisories 146
 System Types
Affected SAP© system types

 

3771065
CVSS
10.0

Affected system type SAP Commerce
Patchday 2026-08
Released on 2026/08/11
Description 3771065 - [CVE-2026-58231] Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
3747367
CVSS
9.9

Affected system type Kernel
Patchday 2026-08
Released on 2026/07/14
Description 3747367 - [CVE-2026-44747] Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP
3765948
CVSS
9.9

Affected system type Java
Patchday 2026-08
Released on 2026/08/11
Description 3765948 - [CVE-2026-44772] Code Injection vulnerability in SAP Manufacturing Integration and Intelligence
3714806
CVSS
9.8

Affected system type Kernel / ABAP
Patchday 2026-08
Released on 2026/08/11
Description 3714806 - [CVE-2026-34265] Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform
3758900
CVSS
9.1

Affected system type Java
Patchday 2026-08
Released on 2026/08/11
Description 3758900 - [CVE-2026-44758] Code Injection vulnerability in Manufacturing Integration and Intelligence
3772411
CVSS
8.8

Affected system type ABAP
Patchday 2026-08
Released on 2026/08/11
Description 3772411 - [CVE-2026-58243] Privilege Escalation vulnerability in SAP ABAP Developer Tools
3732471
CVSS
8.2

Affected system type ABAP
Patchday 2026-08
Released on 2026/05/12
Description 3732471 - [CVE-2026-34259] OS Command Injection Vulnerability in SAP Forecasting & Replenishment
3773203
CVSS
8.1

Affected system type SAP Commerce
Patchday 2026-08
Released on 2026/08/11
Description 3773203 - [CVE-2026-42945] Potential buffer overflow vulnerability affects SAP Commerce Cloud in public‚Äëcloud deployments with NGINX
3756565
CVSS
7.9

Affected system type BI/BO platform
Patchday 2026-08
Released on 2026/08/11
Description 3756565 - [CVE-2026-66763] Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server)
3759854
CVSS
7.6

Affected system type Java
Patchday 2026-08
Released on 2026/08/11
Description 3759854 - [CVE-2026-44763] Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence
3773304
CVSS
7.6

Affected system type SAP Change and...
Patchday 2026-08
Released on 2026/07/14
Description 3773304 - [CVE-2026-58233] Remote Code Execution vulnerability in Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach)
3485073
CVSS
7.5

Affected system type ABAP
Patchday 2026-08
Released on 2026/08/25
Description [CVE-2026-66766] Denial of Service (DoS) due to use of third-party component in SAP S/4HANA (Manage Supply Protection)
3758910
CVSS
7.3

Affected system type Java
Patchday 2026-08
Released on 2026/08/11
Description 3758910 - [CVE-2026-44764] Missing Authorization Check in SAP Manufacturing Integration and Intelligence
3758657
CVSS
7.3

Affected system type Java
Patchday 2026-08
Released on 2026/08/11
Description 3758657 - [CVE-2026-44765] Missing Authorization Check in SAP Manufacturing Integration and Intelligence
3786038
CVSS
7.0

Affected system type SAP Approuter
Patchday 2026-08
Released on 2026/08/11
Description 3786038 - [CVE-2026-58230] Multiple vulnerabilities in SAP Business AI Platform (Approuter)
3753141
CVSS
6.5

Affected system type BI/BO platform
Patchday 2026-08
Released on 2026/08/11
Description 3753141 - [CVE-2026-58248] XML External Entity Injection in SAP BusinessObjects Business Intelligence
3758318
CVSS
6.3

Affected system type Java
Patchday 2026-08
Released on 2026/08/11
Description 3758318 - [CVE-2026-58235] Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)
3721424
CVSS
6.3

Affected system type SAP NetWeaver
Patchday 2026-08
Released on 2026/08/11
Description 3721424 - [CVE-2026-66779] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP
3766473
CVSS
6.3

Affected system type ABAP
Patchday 2026-08
Released on 2026/08/11
Description 3766473 - [CVE-2026-66770] SQL Injection vulnerability in SAP Social Intelligence
3772071
CVSS
6.1

Affected system type SAP UI5
Patchday 2026-08
Released on 2026/08/11
Description 3772071 - [CVE-2026-66771] Cross Site Scripting (XSS) vulnerability in SAPUI5
3540688
CVSS
5.5

Affected system type ABAP
Patchday 2026-08
Released on 2025/07/22
Description 3540688 - [CVE-2025-42947] Code Injection vulnerability in SAP FICA ODN framework
3745182
CVSS
5.5

Affected system type Kernel / ABAP
Patchday 2026-08
Released on 2026/08/11
Description 3745182 - [CVE-2026-58236] OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform
3725940
CVSS
5.3

Affected system type SAPSprint
Patchday 2026-08
Released on 2026/08/11
Description 3725940 - [CVE-2026-40130] Memory Corruption vulnerability in SAPSPrint Service
3756674
CVSS
5.3

Affected system type Kernel / ABAP
Patchday 2026-08
Released on 2026/08/11
Description 3756674 - [CVE-2026-58247] Memory Corruption vulnerability in SAP ABAP Platform
3413033
CVSS
4.3

Affected system type ABAP
Patchday 2026-08
Released on 2026/07/28
Description 3413033 - [CVE-2026-58246 ] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
3781137
CVSS
4.3

Affected system type Java
Patchday 2026-08
Released on 2026/08/11
Description 3781137 - [CVE-2026-58244] Missing Authorization Check in SAP Manufacturing Integration and Intelligence (MII)
3770649
CVSS
4.3

Affected system type BI/BO platform
Patchday 2026-08
Released on 2026/08/11
Description 3770649 - [CVE-2026-66772] Missing Authorization Check in SAP BusinessObjects Business Intelligence Platform (Admin Tools)
3669608
CVSS
4.3

Affected system type ABAP
Patchday 2026-08
Released on 2025/11/19
Description 3669608 - [CVE-2026-66764] Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items)
3752864
CVSS
4.2

Affected system type ABAP
Patchday 2026-08
Released on 2026/08/11
Description 3752864 - [CVE-2026-58241] Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard)
3763028
CVSS
3.8

Affected system type ABAP
Patchday 2026-08
Released on 2026/08/11
Description 3763028 - [CVE-2026-58245] Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)
3739913
CVSS
3.7

Affected system type SAP Data Services
Patchday 2026-08
Released on 2026/08/11
Description 3739913 - [CVE-2026-44762 ] Security Misconfiguration in SAP Data Services Management Console
3770868
CVSS
0.0

Affected system type SAP Commerce Cloud
Patchday 2026-08
Released on 2026/08/11
Description 3770868 - [CVE-2026-34480] Improper Output Encoding Vulnerability in SAP Commerce Cloud and SAP Data Hub (Apache Log4j Core)
3778462
CVSS
0.0

Affected system type SAP Commerce Cloud
Patchday 2026-08
Released on 2026/08/11
Description 3778462 - [Multiple CVEs] Security Vulnerabilities in SAP Commerce Cloud (Search and Navigation)
3757815
CVSS
0.0

Affected system type SAP Commerce Cloud
Patchday 2026-08
Released on 2026/08/11
Description 3757815 - [CVE-2026-5598] Potential Information Disclosure vulnerability in SAP Commerce Cloud (Bouncy Castle Java library)
3692004
CVSS
6.1

Affected system type SAP NetWeaver...
Patchday 2026-07
Released on 2026/04/14
Description 3692004 - [CVE-2026-34257] Open Redirect vulnerability in SAP NetWeaver Application Server ABAP
3747787
CVSS
10.0

Affected system type BTP
Patchday 2026-06
Released on 2026/04/29
Description 3747787 - Malicious open-source packages in SAP Cloud Application Programming Model & MTA Build Tool
3746332
CVSS
9.9

Affected system type ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3746332 - [CVE-2026-44748] XML Signature Wrapping in SAML Authentication in SAP NetWeaver AS ABAP and ABAP Platform
3717897
CVSS
9.8

Affected system type Kernel / ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3717897 - [CVE-2026-27671] Memory Corruption vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform
3733064
CVSS
9.6

Affected system type SAP Commerce Cloud
Patchday 2026-06
Released on 2026/05/12
Description 3733064 - [CVE-2026-34263] Missing authentication check in SAP Commerce Cloud configuration
3748262
CVSS
9.1

Affected system type SAP Commerce Cloud
Patchday 2026-06
Released on 2026/06/09
Description 3748262 - [CVE-2026-22732] Potential Spring Security vulnerability within SAP Commerce Cloud and SAP Data Hub
3747484
CVSS
7.4

Affected system type SAP Commerce Cloud
Patchday 2026-06
Released on 2026/06/09
Description 3747484 - [CVE-2026-29145] Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud
3735546
CVSS
7.1

Affected system type ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3735546 - [CVE-2026-44751] Missing Authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform
3748819
CVSS
6.6

Affected system type ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3748819 - [CVE-2026-44754] Missing caller identification check-in for ODP Data Replication APIs
3751691
CVSS
6.5

Affected system type ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3751691 - [CVE-2026-44744] SQL Injection vulnerability in SAP S/4HANA
3723655
CVSS
6.1

Affected system type Java
Patchday 2026-06
Released on 2026/06/09
Description 3723655 - [CVE-2026-44746] Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java (JDBC Test Servlet)
3715280
CVSS
4.7

Affected system type SAP Solution Manager
Patchday 2026-06
Released on 2026/06/09
Description 3715280 - [CVE-2026-44757] Cross-Site Scripting (XSS) vulnerability in SAP Wily Introscope Enterprise Manager
3718508
CVSS
4.3

Affected system type ABAP
Patchday 2026-06
Released on 2026/05/12
Description 3718508 - [CVE-2026-40134] Missing Authorization Check in SAP Incentive and Commission Management
3687096
CVSS
4.3

Affected system type BI/BO platform
Patchday 2026-06
Released on 2026/06/09
Description 3687096 - [CVE-2026-44755] Email Spoofing vulnerability in SAP Business Objects Business Intelligence Platform
3433366
CVSS
4.3

Affected system type ABAP
Patchday 2026-06
Released on 2026/05/26
Description 3433366 - [CVE-2026-44749] Information Disclosure vulnerability in SAP Gateway
3673181
CVSS
4.3

Affected system type ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3673181 - [CVE-2026-44750] Missing Authorization check in SAP MDG (Review Match Groups Application)
3706000
CVSS
3.7

Affected system type BI/BO platform
Patchday 2026-06
Released on 2026/06/09
Description 3706000 - [CVE-2026-44743] Security Misconfiguration vulnerability in SAP Business Objects
3724838
CVSS
9.6

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3724838 - [CVE-2026-34260] SQL injection vulnerability in SAP S/4HANA (SAP Enterprise Search for ABAP)
3730019
CVSS
6.5

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3730019 - [CVE-2026-40135] OS Command Injection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
3718083
CVSS
6.3

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3718083 - [CVE-2026-40133] Missing Authorization check in SAP S/4HANA Condition Maintenance
3727717
CVSS
6.1

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3727717 - [CVE-2026-40137] Cross-Site Scripting (XSS) vulnerability in Business Server Pages Application (TAF_APPLAUNCHER)
3721959
CVSS
5.4

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3721959 - [CVE-2026-40132] Missing Authorization Check in SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard)
3667593
CVSS
5.4

Affected system type BI/BO platform
Patchday 2026-05
Released on 2026/05/12
Description 3667593 - [CVE-2026-0502] Cross Site Request Forgery (CSRF) in SAP BusinessObjects Business Intelligence Platform
3716450
CVSS
4.8

Affected system type SAP Commerce Cloud
Patchday 2026-05
Released on 2026/05/12
Description 3716450 - [CVE-2025-68161] Potential Improper Certificate Validation in SAP Commerce Cloud (Apache Log4j)
3728690
CVSS
4.7

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3728690 - [CVE-2026-27682] Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages)
3726583
CVSS
4.7

Affected system type SAP UI5
Patchday 2026-05
Released on 2026/05/12
Description 3726583 - [CVE-2026-34258] Content Spoofing vulnerability in SAPUI5 (Search UI)
3713521
CVSS
4.3

Affected system type SAP Financial Consolidation
Patchday 2026-05
Released on 2026/05/12
Description 3713521 - [CVE-2026-40136] Denial of service (DoS) in SAP Financial Consolidation
3735359
CVSS
4.3

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3735359 - [CVE-2026-40129] Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform
3726962
CVSS
3.4

Affected system type HANA platform
Patchday 2026-05
Released on 2026/05/12
Description 3726962 - [CVE-2026-40131] SQL Injection vulnerability in SAP HANA Deployment Infrastructure (HDI) deploy library
3719353
CVSS
9.9

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3719353 - [CVE-2026-27681] SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse
3678282
CVSS
7.5

Affected system type BI/BO platform
Patchday 2026-04
Released on 2026/02/10
Description 3678282 - [CVE-2026-0485] Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platform
3731908
CVSS
7.1

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3731908 - [CVE-2026-34256] Missing Authorization check in SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise)
3715097
CVSS
6.5

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3715097 - [CVE-2026-27677] Missing Authorization check in SAP S/4HANA OData Service (Manage Reference Equipment)
3716767
CVSS
6.5

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3716767 - [CVE-2026-27679] Missing Authorization check in SAP S/4HANA Frontend OData Service (Manage Reference Structures)
3696239
CVSS
6.5

Affected system type BI/BO platform
Patchday 2026-04
Released on 2026/04/14
Description 3696239 - [CVE-2025-64775] Denial of Service Vulnerability in SAP BusinessObjects Business Intelligence Platform
3715177
CVSS
6.5

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3715177 - [CVE-2026-27678] Missing Authorization check in SAP S/4HANA Backend OData Service (Manage Reference Structures)
3705094
CVSS
6.5

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3705094 - [CVE-2026-34261] Missing Authorization check in SAP Business Analytics and SAP Content Management
3680767
CVSS
6.5

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3680767 - [CVE-2026-34264] Information Disclosure vulnerability in SAP Human Capital Management for SAP S/4HANA
3689080
CVSS
6.4

Affected system type ABAP
Patchday 2026-04
Released on 2026/03/10
Description 3689080 - [CVE-2026-24316] Server-Side Request Forgery (SSRF) in SAP NetWeaver Application Server for ABAP
3645228
CVSS
6.1

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3645228 - [CVE-2026-0512] Cross-Site Scripting (XSS) vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog)
3719397
CVSS
6.1

Affected system type Java
Patchday 2026-04
Released on 2026/04/14
Description 3719397 - [CVE-2026-27674] Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java)
3730639
CVSS
5.0

Affected system type HANA platform
Patchday 2026-04
Released on 2026/04/14
Description 3730639 - [CVE-2026-34262] Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
3703813
CVSS
4.9

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3703813 - [CVE-2026-27673] Missing Authorization Check in SAP S/4HANA (Private Cloud and On-Premise)
3530544
CVSS
4.3

Affected system type ABAP
Patchday 2026-04
Released on 2025/11/11
Description 3530544 - [CVE-2025-42899] Missing Authorization check in SAP S4CORE (Manage Journal Entries)
3711682
CVSS
4.3

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3711682 - [CVE-2026-27676] Missing Authorization check in SAP S/4HANA OData Service (Manage Technical Object Structures)
3703276
CVSS
4.3

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3703276 - [CVE-2026-27672] Missing Authorization check in Material Master Application
3702191
CVSS
4.2

Affected system type BI/BO platform
Patchday 2026-04
Released on 2026/04/14
Description 3702191 - [CVE-2026-24318] Insecure Session Management vulnerability in SAP BusinessObjects Business Intelligence Platform
3698216
CVSS
4.1

Affected system type BI/BO platform
Patchday 2026-04
Released on 2026/04/14
Description 3698216 - [CVE-2026-27683] Reflected cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform
3665042
CVSS
3.1

Affected system type ABAP
Patchday 2026-04
Released on 2026/03/10
Description 3665042 - [CVE-2026-27680] CSS Injection vulnerability in SAP NetWeaver Application Server ABAP
3723097
CVSS
2.0

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3723097 - [CVE-2026-27675] Code Injection vulnerability in SAP Landscape Transformation
3698553
CVSS
9.8

Affected system type Java
Patchday 2026-03
Released on 2026/03/10
Description 3698553 - [CVE-2019-17571 ] Code Injection vulnerability in SAP Quotation Management Insurance application (FS-QUO)
3714585
CVSS
9.1

Affected system type Java
Patchday 2026-03
Released on 2026/03/10
Description 3714585 - [ CVE-2026-27685] Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration
3697567
CVSS
8.8

Affected system type ABAP
Patchday 2026-03
Released on 2026/02/10
Description 3697567 - [CVE-2026-23687] XML Signature Wrapping in SAP NetWeaver AS ABAP and ABAP Platform
3719502
CVSS
7.7

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3719502 - [CVE-2026-27689] Denial of service (DOS) in SAP Supply Chain Management
3695912
CVSS
6.5

Affected system type BI/BO platform
Patchday 2026-03
Released on 2026/02/10
Description 3695912 - [CVE-2026-24324] Denial of service (DOS) vulnerability in SAP BusinessObjects Business Intelligence Platform (AdminTools)
3672622
CVSS
6.5

Affected system type ABAP
Patchday 2026-03
Released on 2026/02/10
Description 3672622 - [CVE-2026-0484] Missing Authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA
3697355
CVSS
6.4

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3697355 - [CVE-2026-27684] SQL Injection Vulnerability in SAP NetWeaver (Feedback Notification)
3703856
CVSS
6.4

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3703856 - [CVE-2026-24309] Missing Authorization check in SAP NetWeaver Application Server for ABAP
3693543
CVSS
6.1

Affected system type SAP Business One
Patchday 2026-03
Released on 2026/03/10
Description 3693543 - [CVE-2026-0489] DOM-based Cross-Site Scripting (XSS) Vulnerability in SAP Business One (Job Service)
3703385
CVSS
5.9

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3703385 - [CVE-2026-27686] Missing Authorization check in SAP Business Warehouse (Service API)
3701020
CVSS
5.8

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3701020 - [CVE-2026-27687] Missing Authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal
3708457
CVSS
5.6

Affected system type SAP Customer Checkout
Patchday 2026-03
Released on 2026/03/10
Description 3708457 - [CVE-2026-24311] Insecure Storage Protection vulnerability in SAP Customer Checkout 2.0
3707930
CVSS
5.0

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3707930 - [CVE-2026-24313] Missing Authorization check in SAP Solution Tools Plug-In (ST-PI)
3699761
CVSS
5.0

Affected system type SAP GUI / Frontend
Patchday 2026-03
Released on 2026/03/10
Description 3699761 - [CVE-2026-24317] DLL Hijacking vulnerability in SAP GUI for Windows with active GuiXT
3704740
CVSS
5.0

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3704740 - [CVE-2026-27688] Missing Authorization check in SAP NetWeaver Application Server for ABAP
3396109
CVSS
4.7

Affected system type ABAP
Patchday 2026-03
Released on 2024/02/13
Description 3396109 - [CVE-2024-22128] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Business Client for HTML
3646297
CVSS
4.3

Affected system type ABAP
Patchday 2026-03
Released on 2026/02/24
Description 3646297 - [CVE-2026-24314] Information Disclosure vulnerability in SAP S/4HANA (Manage Payment Media)
3700960
CVSS
4.3

Affected system type Java
Patchday 2026-03
Released on 2026/03/10
Description 3700960 - [Multiple CVEs] Denial of Service due to Outdated OpenSSL Version in SAP NetWeaver AS Java (Adobe Document Services)
3694383
CVSS
3.5

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3694383 - [CVE-2026-24310] Missing Authorization check in SAP NetWeaver Application Server for ABAP
3697099
CVSS
9.9

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0488] Code Injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor)
3674774
CVSS
9.6

Affected system type Kernel
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0509] Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
3697979
CVSS
9.1

Affected system type ABAP
Patchday 2026-02
Released on 2026/01/13
Description [CVE-2026-0491] Code Injection vulnerability in SAP Landscape Transformation
3697256
CVSS
7.7

Affected system type BI/BO platform
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24325] Cross Site Scripting (XSS) vulnerability in SAP BusinessObjects Enterprise (Central Management Console)
3705882
CVSS
7.7

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24322] Missing Authorization check in SAP Solution Tools Plug-In (ST-PI)
3703092
CVSS
7.7

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23689] Denial of service (DOS) in SAP Supply Chain Management
3654236
CVSS
7.5

Affected system type BI/BO platform
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0490] Denial of service (DOS) in SAP BusinessObjects BI Platform
3692405
CVSS
7.4

Affected system type SAP Commerce Cloud
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2025-12383] Race Condition in SAP Commerce Cloud
3674246
CVSS
7.3

Affected system type BI/BO platform
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0508] Open Redirect vulnerability in SAP BusinessObjects Business Intelligence Platform
3678417
CVSS
6.1

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0505] Multiple vulnerabilities in BSP Applications of SAP Document Management System
3688319
CVSS
6.1

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24328] Open Redirection vulnerability in Business Server Pages Application (TAF_APPLAUNCHER)
3503138
CVSS
6.0

Affected system type SAP GUI / Frontend
Patchday 2026-02
Released on 2025/01/14
Description [CVE-2025-0059] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML)
3689543
CVSS
5.9

Affected system type SAP Commerce Cloud
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23684] Race condition vulnerability in SAP Commerce Cloud
3679346
CVSS
5.8

Affected system type SAP Business One
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24319] Information Disclosure Vulnerability in SAP Business One (B1 Client Memory Dump Files)
3687771
CVSS
5.3

Affected system type SAP Commerce Cloud
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24321] Information Disclosure vulnerability in SAP Commerce Cloud
3710111
CVSS
5.2

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24312] Missing authorization check in SAP Business Workflow
3691645
CVSS
5.2

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0486] Missing Authorization Check in ABAP based SAP systems
3678009
CVSS
5.2

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24326] Missing authorization check in SAP S/4HANA Defense & Security (Disconnected Operations)
3687285
CVSS
4.4

Affected system type Java
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23685] Insecure Deserialization vulnerability in SAP NetWeaver (JMS service)
3680390
CVSS
4.3

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24327] Missing Authorization Check in SAP Strategic Enterprise Management (Balanced Scorecard in BSP Application)
3122486
CVSS
4.3

Affected system type ABAP
Patchday 2026-02
Released on 2026/01/27
Description [CVE-2026-23683] Missing Authorization check in SAP Fiori App (Intercompany Balance Reconciliation)
3215823
CVSS
4.3

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23688] Missing Authorization check in SAP Fiori App (Manage Service Entry Sheets - Lean Services)
3680416
CVSS
4.3

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23681] Missing Authorization check in a function module in SAP Support Tools Plug-In
3673213
CVSS
3.4

Affected system type Java
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23686] CRLF Injection vulnerability in SAP NetWeaver Application Server Java
3678313
CVSS
3.1

Affected system type Kernel
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24320] Memory Corruption vulnerability in SAP NetWeaver and ABAP Platform (Application Server ABAP)
3687749
CVSS
9.9

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0501] SQL Injection Vulnerability in SAP S/4HANA Private Cloud and On-Premise (Financials – General Ledger)
3683579
CVSS
9.6

Affected system type SAP Commerce Cloud
Patchday 2026-01
Released on 2025/12/09
Description Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud
3668679
CVSS
9.6

Affected system type SAP Solution Manager...
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0500] Remote code execution in SAP Wily Introscope Enterprise Manager (WorkStation)
3685286
CVSS
9.1

Affected system type SAP Adaptive Server...
Patchday 2026-01
Released on 2025/12/09
Description [CVE-2025-42928] Deserialization Vulnerability in SAP jConnect - SDK for ASE
3694242
CVSS
9.1

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0498] Code Injection vulnerability in SAP S/4HANA (Private Cloud and On-Premise)
3691059
CVSS
8.8

Affected system type HANA platform
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0492] Privilege escalation vulnerability in SAP HANA database
3675151
CVSS
8.4

Affected system type Kernel
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0507] OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK
3688703
CVSS
8.1

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0506] Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
3565506
CVSS
8.1

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0511] Multiple vulnerabilities in SAP Fiori App (Intercompany Balance Reconciliation)
3681523
CVSS
6.4

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0503] Missing Authorization check in SAP ERP Central Component and SAP S/4HANA (SAP EHS Management)
3666061
CVSS
6.1

Affected system type SAP Business Connector
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0514] Cross-Site Scripting (XSS) vulnerability in SAP Business Connector
3687372
CVSS
6.1

Affected system type Java
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0499] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3638716
CVSS
4.7

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0513] Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog)
3677111
CVSS
4.3

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0497] Missing Authorization check in Business Server Pages Application (Product Designer Web UI)
3655227
CVSS
4.3

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0494] Information Disclosure vulnerability in SAP Fiori App (Intercompany Balance Reconciliation)
3655229
CVSS
4.3

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0493] Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App (Intercompany Balance Reconciliation)
3657998
CVSS
3.8

Affected system type SAP IDM
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0504] Insufficient Input Handling in JNDI Operations of SAP Identity Management
3593356
CVSS
3.0

Affected system type Java
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0510] Obsolete Encryption Algorithm Used in NW AS Java UME User Mapping