We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

×

Yikes, there is work to do!
This time we found critical correction advisiories. We count 130 and the highest CVSS score is 10.0.

 

Severity
SAP© Security advisories 130
 System Types
Affected SAP© system types

 

3753495
CVSS
9.1

Affected system type SAP Commerce Cloud
Patchday 2026-07
Released on 2026/07/14
Description 3753495 - [CVE-2026-44761] Insecure Sample Credentials in SAP Commerce Cloud
3720138
CVSS
9.1

Affected system type SAP Approuter
Patchday 2026-07
Released on 2026/07/14
Description 3720138 - [CVE-2026-27690] HTTP Request Smuggling in SAP Approuter
3727078
CVSS
9.0

Affected system type Java
Patchday 2026-07
Released on 2026/06/09
Description 3727078 - [CVE-2026-40128] Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container)
3758101
CVSS
8.8

Affected system type SAP Edge Integration
Patchday 2026-07
Released on 2026/07/14
Description 3758101 - [CVE-2026-40860] Multiple vulnerabilities in Apache Camel within SAP Integration Suite (Edge Integration Cell)
3692165
CVSS
8.4

Affected system type SAProuter
Patchday 2026-07
Released on 2026/07/14
Description 3692165 - [CVE-2026-0487] DLL Hijacking vulnerability in SAProuter on Microsoft Windows
3748227
CVSS
8.2

Affected system type Java
Patchday 2026-07
Released on 2026/07/14
Description 3748227 - [CVE-2026-44752] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java(Configuration Wizard)
3763800
CVSS
8.1

Affected system type SAP Commerce Cloud
Patchday 2026-07
Released on 2026/07/14
Description 3763800 - [Multiple CVEs] Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud
3741519
CVSS
8.1

Affected system type SAP Approuter
Patchday 2026-07
Released on 2026/07/14
Description 3741519 - [CVE-2026-44745] Open Redirect vulnerability in SAP Approuter
3773304
CVSS
7.6

Affected system type SAP Change and...
Patchday 2026-07
Released on 2026/07/14
Description 3773304 - [CVE-2026-58233] Remote Code Execution vulnerability in SAP Change and Transport System Attach Tool (ctsattach)
3746678
CVSS
6.1

Affected system type Java
Patchday 2026-07
Released on 2026/07/14
Description 3746678 - [CVE-2026-44759] Cross Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3692004
CVSS
6.1

Affected system type SAP NetWeaver...
Patchday 2026-07
Released on 2026/04/14
Description 3692004 - [CVE-2026-34257] Open Redirect vulnerability in SAP NetWeaver Application Server ABAP
3537373
CVSS
5.5

Affected system type ABAP
Patchday 2026-07
Released on 2026/07/14
Description 3537373 - [CVE-2026-44769] SQL Injection vulnerability in SAP S/4HANA Project Management (PPM-PRO)
3754659
CVSS
4.7

Affected system type ABAP
Patchday 2026-07
Released on 2026/07/14
Description 3754659 - [CVE-2026-44760] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on Business Server Pages)
3515598
CVSS
4.3

Affected system type ABAP
Patchday 2026-07
Released on 2026/07/14
Description 3515598 - [CVE-2026-44771] Missing Authorization check in SAP S/4HANA (Draft operation)
3713902
CVSS
4.3

Affected system type ABAP
Patchday 2026-07
Released on 2026/07/14
Description 3713902 - [CVE-2026-44770] Missing Authorization check in SAP S/4 HANA (Create Single Payment)
3682699
CVSS
4.2

Affected system type SAP Fiori
Patchday 2026-07
Released on 2026/06/09
Description 3682699 - [CVE-2026-24315] Path Traversal Vulnerability in SAP Fiori (launchpad)
3155685
CVSS
4.1

Affected system type ABAP
Patchday 2026-07
Released on 2026/07/14
Description 3155685 - [CVE-2026-44768] Security misconfiguration in SAP CRM (WebClient UI)
3732522
CVSS
3.7

Affected system type SAP HANA Platform
Patchday 2026-07
Released on 2026/07/14
Description 3732522 - [CVE-2026-44753] - Information Disclosure vulnerability in SAP HANA Extended Application Services classic model (User Self Service)
3726899
CVSS
3.3

Affected system type Java
Patchday 2026-07
Released on 2026/06/09
Description 3726899 - [CVE-2025-68161] Potential vulnerability in Apache Log4j library used by SAP NetWeaver AS Java
3747787
CVSS
10.0

Affected system type BTP
Patchday 2026-06
Released on 2026/04/29
Description 3747787 - Malicious open-source packages in SAP Cloud Application Programming Model & MTA Build Tool
3746332
CVSS
9.9

Affected system type ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3746332 - [CVE-2026-44748] XML Signature Wrapping in SAML Authentication in SAP NetWeaver AS ABAP and ABAP Platform
3717897
CVSS
9.8

Affected system type Kernel / ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3717897 - [CVE-2026-27671] Memory Corruption vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform
3733064
CVSS
9.6

Affected system type SAP Commerce Cloud
Patchday 2026-06
Released on 2026/05/12
Description 3733064 - [CVE-2026-34263] Missing authentication check in SAP Commerce Cloud configuration
3748262
CVSS
9.1

Affected system type SAP Commerce Cloud
Patchday 2026-06
Released on 2026/06/09
Description 3748262 - [CVE-2026-22732] Potential Spring Security vulnerability within SAP Commerce Cloud and SAP Data Hub
3747484
CVSS
7.4

Affected system type SAP Commerce Cloud
Patchday 2026-06
Released on 2026/06/09
Description 3747484 - [CVE-2026-29145] Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud
3735546
CVSS
7.1

Affected system type ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3735546 - [CVE-2026-44751] Missing Authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform
3748819
CVSS
6.6

Affected system type ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3748819 - [CVE-2026-44754] Missing caller identification check-in for ODP Data Replication APIs
3751691
CVSS
6.5

Affected system type ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3751691 - [CVE-2026-44744] SQL Injection vulnerability in SAP S/4HANA
3723655
CVSS
6.1

Affected system type Java
Patchday 2026-06
Released on 2026/06/09
Description 3723655 - [CVE-2026-44746] Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java (JDBC Test Servlet)
3715280
CVSS
4.7

Affected system type SAP Solution Manager
Patchday 2026-06
Released on 2026/06/09
Description 3715280 - [CVE-2026-44757] Cross-Site Scripting (XSS) vulnerability in SAP Wily Introscope Enterprise Manager
3433366
CVSS
4.3

Affected system type ABAP
Patchday 2026-06
Released on 2026/05/26
Description 3433366 - [CVE-2026-44749] Information Disclosure vulnerability in SAP Gateway
3673181
CVSS
4.3

Affected system type ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3673181 - [CVE-2026-44750] Missing Authorization check in SAP MDG (Review Match Groups Application)
3718508
CVSS
4.3

Affected system type ABAP
Patchday 2026-06
Released on 2026/05/12
Description 3718508 - [CVE-2026-40134] Missing Authorization Check in SAP Incentive and Commission Management
3687096
CVSS
4.3

Affected system type BI/BO platform
Patchday 2026-06
Released on 2026/06/09
Description 3687096 - [CVE-2026-44755] Email Spoofing vulnerability in SAP Business Objects Business Intelligence Platform
3706000
CVSS
3.7

Affected system type BI/BO platform
Patchday 2026-06
Released on 2026/06/09
Description 3706000 - [CVE-2026-44743] Security Misconfiguration vulnerability in SAP Business Objects
3724838
CVSS
9.6

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3724838 - [CVE-2026-34260] SQL injection vulnerability in SAP S/4HANA (SAP Enterprise Search for ABAP)
3730019
CVSS
6.5

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3730019 - [CVE-2026-40135] OS Command Injection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
3718083
CVSS
6.3

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3718083 - [CVE-2026-40133] Missing Authorization check in SAP S/4HANA Condition Maintenance
3727717
CVSS
6.1

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3727717 - [CVE-2026-40137] Cross-Site Scripting (XSS) vulnerability in Business Server Pages Application (TAF_APPLAUNCHER)
3721959
CVSS
5.4

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3721959 - [CVE-2026-40132] Missing Authorization Check in SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard)
3667593
CVSS
5.4

Affected system type BI/BO platform
Patchday 2026-05
Released on 2026/05/12
Description 3667593 - [CVE-2026-0502] Cross Site Request Forgery (CSRF) in SAP BusinessObjects Business Intelligence Platform
3716450
CVSS
4.8

Affected system type SAP Commerce Cloud
Patchday 2026-05
Released on 2026/05/12
Description 3716450 - [CVE-2025-68161] Potential Improper Certificate Validation in SAP Commerce Cloud (Apache Log4j)
3726583
CVSS
4.7

Affected system type SAP UI5
Patchday 2026-05
Released on 2026/05/12
Description 3726583 - [CVE-2026-34258] Content Spoofing vulnerability in SAPUI5 (Search UI)
3728690
CVSS
4.7

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3728690 - [CVE-2026-27682] Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages)
3713521
CVSS
4.3

Affected system type SAP Financial Consolidation
Patchday 2026-05
Released on 2026/05/12
Description 3713521 - [CVE-2026-40136] Denial of service (DoS) in SAP Financial Consolidation
3735359
CVSS
4.3

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3735359 - [CVE-2026-40129] Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform
3726962
CVSS
3.4

Affected system type HANA platform
Patchday 2026-05
Released on 2026/05/12
Description 3726962 - [CVE-2026-40131] SQL Injection vulnerability in SAP HANA Deployment Infrastructure (HDI) deploy library
3719353
CVSS
9.9

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3719353 - [CVE-2026-27681] SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse
3678282
CVSS
7.5

Affected system type BI/BO platform
Patchday 2026-04
Released on 2026/02/10
Description 3678282 - [CVE-2026-0485] Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platform
3731908
CVSS
7.1

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3731908 - [CVE-2026-34256] Missing Authorization check in SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise)
3680767
CVSS
6.5

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3680767 - [CVE-2026-34264] Information Disclosure vulnerability in SAP Human Capital Management for SAP S/4HANA
3696239
CVSS
6.5

Affected system type BI/BO platform
Patchday 2026-04
Released on 2026/04/14
Description 3696239 - [CVE-2025-64775] Denial of Service Vulnerability in SAP BusinessObjects Business Intelligence Platform
3715097
CVSS
6.5

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3715097 - [CVE-2026-27677] Missing Authorization check in SAP S/4HANA OData Service (Manage Reference Equipment)
3716767
CVSS
6.5

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3716767 - [CVE-2026-27679] Missing Authorization check in SAP S/4HANA Frontend OData Service (Manage Reference Structures)
3705094
CVSS
6.5

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3705094 - [CVE-2026-34261] Missing Authorization check in SAP Business Analytics and SAP Content Management
3715177
CVSS
6.5

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3715177 - [CVE-2026-27678] Missing Authorization check in SAP S/4HANA Backend OData Service (Manage Reference Structures)
3689080
CVSS
6.4

Affected system type ABAP
Patchday 2026-04
Released on 2026/03/10
Description 3689080 - [CVE-2026-24316] Server-Side Request Forgery (SSRF) in SAP NetWeaver Application Server for ABAP
3719397
CVSS
6.1

Affected system type Java
Patchday 2026-04
Released on 2026/04/14
Description 3719397 - [CVE-2026-27674] Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java)
3645228
CVSS
6.1

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3645228 - [CVE-2026-0512] Cross-Site Scripting (XSS) vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog)
3730639
CVSS
5.0

Affected system type HANA platform
Patchday 2026-04
Released on 2026/04/14
Description 3730639 - [CVE-2026-34262] Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
3703813
CVSS
4.9

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3703813 - [CVE-2026-27673] Missing Authorization Check in SAP S/4HANA (Private Cloud and On-Premise)
3530544
CVSS
4.3

Affected system type ABAP
Patchday 2026-04
Released on 2025/11/11
Description 3530544 - [CVE-2025-42899] Missing Authorization check in SAP S4CORE (Manage Journal Entries)
3703276
CVSS
4.3

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3703276 - [CVE-2026-27672] Missing Authorization check in Material Master Application
3711682
CVSS
4.3

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3711682 - [CVE-2026-27676] Missing Authorization check in SAP S/4HANA OData Service (Manage Technical Object Structures)
3702191
CVSS
4.2

Affected system type BI/BO platform
Patchday 2026-04
Released on 2026/04/14
Description 3702191 - [CVE-2026-24318] Insecure Session Management vulnerability in SAP BusinessObjects Business Intelligence Platform
3698216
CVSS
4.1

Affected system type BI/BO platform
Patchday 2026-04
Released on 2026/04/14
Description 3698216 - [CVE-2026-27683] Reflected cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform
3665042
CVSS
3.1

Affected system type ABAP
Patchday 2026-04
Released on 2026/03/10
Description 3665042 - [CVE-2026-27680] CSS Injection vulnerability in SAP NetWeaver Application Server ABAP
3723097
CVSS
2.0

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3723097 - [CVE-2026-27675] Code Injection vulnerability in SAP Landscape Transformation
3698553
CVSS
9.8

Affected system type Java
Patchday 2026-03
Released on 2026/03/10
Description 3698553 - [CVE-2019-17571 ] Code Injection vulnerability in SAP Quotation Management Insurance application (FS-QUO)
3714585
CVSS
9.1

Affected system type Java
Patchday 2026-03
Released on 2026/03/10
Description 3714585 - [ CVE-2026-27685] Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration
3697567
CVSS
8.8

Affected system type ABAP
Patchday 2026-03
Released on 2026/02/10
Description 3697567 - [CVE-2026-23687] XML Signature Wrapping in SAP NetWeaver AS ABAP and ABAP Platform
3719502
CVSS
7.7

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3719502 - [CVE-2026-27689] Denial of service (DOS) in SAP Supply Chain Management
3695912
CVSS
6.5

Affected system type BI/BO platform
Patchday 2026-03
Released on 2026/02/10
Description 3695912 - [CVE-2026-24324] Denial of service (DOS) vulnerability in SAP BusinessObjects Business Intelligence Platform (AdminTools)
3672622
CVSS
6.5

Affected system type ABAP
Patchday 2026-03
Released on 2026/02/10
Description 3672622 - [CVE-2026-0484] Missing Authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA
3697355
CVSS
6.4

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3697355 - [CVE-2026-27684] SQL Injection Vulnerability in SAP NetWeaver (Feedback Notification)
3703856
CVSS
6.4

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3703856 - [CVE-2026-24309] Missing Authorization check in SAP NetWeaver Application Server for ABAP
3693543
CVSS
6.1

Affected system type SAP Business One
Patchday 2026-03
Released on 2026/03/10
Description 3693543 - [CVE-2026-0489] DOM-based Cross-Site Scripting (XSS) Vulnerability in SAP Business One (Job Service)
3703385
CVSS
5.9

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3703385 - [CVE-2026-27686] Missing Authorization check in SAP Business Warehouse (Service API)
3701020
CVSS
5.8

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3701020 - [CVE-2026-27687] Missing Authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal
3708457
CVSS
5.6

Affected system type SAP Customer Checkout
Patchday 2026-03
Released on 2026/03/10
Description 3708457 - [CVE-2026-24311] Insecure Storage Protection vulnerability in SAP Customer Checkout 2.0
3704740
CVSS
5.0

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3704740 - [CVE-2026-27688] Missing Authorization check in SAP NetWeaver Application Server for ABAP
3707930
CVSS
5.0

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3707930 - [CVE-2026-24313] Missing Authorization check in SAP Solution Tools Plug-In (ST-PI)
3699761
CVSS
5.0

Affected system type SAP GUI / Frontend
Patchday 2026-03
Released on 2026/03/10
Description 3699761 - [CVE-2026-24317] DLL Hijacking vulnerability in SAP GUI for Windows with active GuiXT
3396109
CVSS
4.7

Affected system type ABAP
Patchday 2026-03
Released on 2024/02/13
Description 3396109 - [CVE-2024-22128] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Business Client for HTML
3646297
CVSS
4.3

Affected system type ABAP
Patchday 2026-03
Released on 2026/02/24
Description 3646297 - [CVE-2026-24314] Information Disclosure vulnerability in SAP S/4HANA (Manage Payment Media)
3700960
CVSS
4.3

Affected system type Java
Patchday 2026-03
Released on 2026/03/10
Description 3700960 - [Multiple CVEs] Denial of Service due to Outdated OpenSSL Version in SAP NetWeaver AS Java (Adobe Document Services)
3694383
CVSS
3.5

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3694383 - [CVE-2026-24310] Missing Authorization check in SAP NetWeaver Application Server for ABAP
3697099
CVSS
9.9

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0488] Code Injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor)
3674774
CVSS
9.6

Affected system type Kernel
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0509] Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
3697979
CVSS
9.1

Affected system type ABAP
Patchday 2026-02
Released on 2026/01/13
Description [CVE-2026-0491] Code Injection vulnerability in SAP Landscape Transformation
3705882
CVSS
7.7

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24322] Missing Authorization check in SAP Solution Tools Plug-In (ST-PI)
3703092
CVSS
7.7

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23689] Denial of service (DOS) in SAP Supply Chain Management
3697256
CVSS
7.7

Affected system type BI/BO platform
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24325] Cross Site Scripting (XSS) vulnerability in SAP BusinessObjects Enterprise (Central Management Console)
3654236
CVSS
7.5

Affected system type BI/BO platform
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0490] Denial of service (DOS) in SAP BusinessObjects BI Platform
3692405
CVSS
7.4

Affected system type SAP Commerce Cloud
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2025-12383] Race Condition in SAP Commerce Cloud
3674246
CVSS
7.3

Affected system type BI/BO platform
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0508] Open Redirect vulnerability in SAP BusinessObjects Business Intelligence Platform
3678417
CVSS
6.1

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0505] Multiple vulnerabilities in BSP Applications of SAP Document Management System
3688319
CVSS
6.1

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24328] Open Redirection vulnerability in Business Server Pages Application (TAF_APPLAUNCHER)
3503138
CVSS
6.0

Affected system type SAP GUI / Frontend
Patchday 2026-02
Released on 2025/01/14
Description [CVE-2025-0059] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML)
3689543
CVSS
5.9

Affected system type SAP Commerce Cloud
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23684] Race condition vulnerability in SAP Commerce Cloud
3679346
CVSS
5.8

Affected system type SAP Business One
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24319] Information Disclosure Vulnerability in SAP Business One (B1 Client Memory Dump Files)
3687771
CVSS
5.3

Affected system type SAP Commerce Cloud
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24321] Information Disclosure vulnerability in SAP Commerce Cloud
3691645
CVSS
5.2

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0486] Missing Authorization Check in ABAP based SAP systems
3678009
CVSS
5.2

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24326] Missing authorization check in SAP S/4HANA Defense & Security (Disconnected Operations)
3710111
CVSS
5.2

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24312] Missing authorization check in SAP Business Workflow
3687285
CVSS
4.4

Affected system type Java
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23685] Insecure Deserialization vulnerability in SAP NetWeaver (JMS service)
3215823
CVSS
4.3

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23688] Missing Authorization check in SAP Fiori App (Manage Service Entry Sheets - Lean Services)
3680390
CVSS
4.3

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24327] Missing Authorization Check in SAP Strategic Enterprise Management (Balanced Scorecard in BSP Application)
3122486
CVSS
4.3

Affected system type ABAP
Patchday 2026-02
Released on 2026/01/27
Description [CVE-2026-23683] Missing Authorization check in SAP Fiori App (Intercompany Balance Reconciliation)
3680416
CVSS
4.3

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23681] Missing Authorization check in a function module in SAP Support Tools Plug-In
3673213
CVSS
3.4

Affected system type Java
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23686] CRLF Injection vulnerability in SAP NetWeaver Application Server Java
3678313
CVSS
3.1

Affected system type Kernel
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24320] Memory Corruption vulnerability in SAP NetWeaver and ABAP Platform (Application Server ABAP)
3687749
CVSS
9.9

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0501] SQL Injection Vulnerability in SAP S/4HANA Private Cloud and On-Premise (Financials – General Ledger)
3683579
CVSS
9.6

Affected system type SAP Commerce Cloud
Patchday 2026-01
Released on 2025/12/09
Description Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud
3668679
CVSS
9.6

Affected system type SAP Solution Manager...
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0500] Remote code execution in SAP Wily Introscope Enterprise Manager (WorkStation)
3694242
CVSS
9.1

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0498] Code Injection vulnerability in SAP S/4HANA (Private Cloud and On-Premise)
3685286
CVSS
9.1

Affected system type SAP Adaptive Server...
Patchday 2026-01
Released on 2025/12/09
Description [CVE-2025-42928] Deserialization Vulnerability in SAP jConnect - SDK for ASE
3691059
CVSS
8.8

Affected system type HANA platform
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0492] Privilege escalation vulnerability in SAP HANA database
3675151
CVSS
8.4

Affected system type Kernel
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0507] OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK
3688703
CVSS
8.1

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0506] Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
3565506
CVSS
8.1

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0511] Multiple vulnerabilities in SAP Fiori App (Intercompany Balance Reconciliation)
3681523
CVSS
6.4

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0503] Missing Authorization check in SAP ERP Central Component and SAP S/4HANA (SAP EHS Management)
3666061
CVSS
6.1

Affected system type SAP Business Connector
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0514] Cross-Site Scripting (XSS) vulnerability in SAP Business Connector
3687372
CVSS
6.1

Affected system type Java
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0499] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3638716
CVSS
4.7

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0513] Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog)
3677111
CVSS
4.3

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0497] Missing Authorization check in Business Server Pages Application (Product Designer Web UI)
3655229
CVSS
4.3

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0493] Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App (Intercompany Balance Reconciliation)
3655227
CVSS
4.3

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0494] Information Disclosure vulnerability in SAP Fiori App (Intercompany Balance Reconciliation)
3657998
CVSS
3.8

Affected system type SAP IDM
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0504] Insufficient Input Handling in JNDI Operations of SAP Identity Management
3593356
CVSS
3.0

Affected system type Java
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0510] Obsolete Encryption Algorithm Used in NW AS Java UME User Mapping