SAP’s March 2026 Patch Day delivered 15 security notes addressing vulnerabilities across its portfolio, including two critical issues that could lead to remote code execution and full system compromise. The most severe item highlighted is CVE-2019-17571 (CVSS 9.8) in SAP Quotation Management Insurance (FS-QUO 800), tied to an outdated Apache Log4j SocketServer component that accepts and deserializes serialized log events without authentication, enabling unauthenticated attackers to execute arbitrary code; reporting noted this is the first SAP patch specifically issued for FS-QUO 800 despite the CVE dating to 2019.
SAP also patched CVE-2026-27685 (CVSS 9.1) affecting SAP NetWeaver Enterprise Portal Administration (EP-RUNTIME 7.50), described as an insecure deserialization condition where a privileged user can upload malicious/untrusted content that, when deserialized by the server, can significantly impact confidentiality, integrity, and availability—effectively enabling host-level control; this is addressed in SAP Security Note 3714585. Additional fixes included a high-severity denial-of-service issue (CVE-2026-27689, CVSS 7.7) in SAP Supply Chain Management impacting multiple SCMAPO, S4CORE, S4COREOP, and SCM versions, exploitable by an authenticated low-privileged attacker to disrupt availability over the network.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-10, the Canadian Centre for Cyber Security published a monthly rollup advisory highlighting SAP's March 2026 security updates. It specifically called attention to CVE-2026-27685 in SAP NetWeaver Enterprise Portal Administration and urged administrators to review advisories and apply mitigations and updates.
On 2026-03-10, SAP released its March 2026 Security Patch Day updates, including Security Note 3714585 to fix CVE-2026-27685, an insecure deserialization flaw in SAP NetWeaver Enterprise Portal Administration. The patch bundle also addressed other SAP vulnerabilities, including critical and high-severity issues in FS-QUO and SAP Supply Chain Management.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.