SAP released multiple security updates addressing critical vulnerabilities across core enterprise products, including SAP NetWeaver, SAP S/4HANA, SAP Commerce Cloud, SAP Business Warehouse, SAP Business Planning and Consolidation, SAP Kernel, ABAP Platform, SAP NetWeaver Application Server Java, and SAP Forecasting & Replenishment. The fixes covered at least 15 vulnerabilities in both the April-to-June advisories, with several flaws rated critical and carrying CVSS scores from 9.0 to 9.9. Reported impacts included SQL injection, remote code execution, operating system command execution, directory traversal, memory corruption, sensitive data exposure, denial of service, privilege abuse, and potential full compromise of confidentiality, integrity, and availability.
Among the most severe issues, CVE-2026-27681 affected SAP Business Planning and Consolidation and SAP Business Warehouse, allowing a low-privileged authenticated attacker to upload a file containing SQL commands and execute arbitrary database operations; SAP said a temporary mitigation was to revoke the S_GUI authorization object with Activity 60 (Upload) where possible. Additional high-risk flaws included CVE-2026-34260 and CVE-2026-34263 in SAP S/4HANA, SAP Commerce Cloud, and SAP Forecasting & Replenishment, each scored 9.6, as well as critical June issues in NetWeaver-related components that could enable unauthorized access, file-processing abuse, and system compromise. SAP and national defenders urged organizations to apply vendor-specified patches immediately.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
SAP released June 2026 security updates remediating 15 vulnerabilities, including four critical issues affecting SAP NetWeaver AS ABAP, ABAP Platform, SAP Kernel, and SAP NetWeaver Application Server Java. The flaws could enable unauthorized data access, privilege abuse, directory traversal, file processing abuse, memory corruption, and full compromise of confidentiality, integrity, and availability.
SAP published its June 2026 Security Notes, as reflected in the vendor's Security Notes & News reference. This marks the vendor release point for that month's security advisories.
SAP released security updates in May 2026 addressing 15 vulnerabilities across multiple products, including critical flaws affecting SAP S/4HANA, SAP Commerce Cloud, and SAP Forecasting & Replenishment. The patched issues included risks such as SQL injection, remote code execution, OS command execution, sensitive data exposure, and denial of service.
SAP released April 2026 security updates that fixed CVE-2026-27681, a critical SQL injection vulnerability affecting SAP Business Planning and Consolidation and SAP Business Warehouse. The flaw could let a low-privileged authenticated attacker execute arbitrary SQL commands and alter or delete database contents.
SAP released security updates across its product portfolio to fix 20 vulnerabilities, including three critical flaws. The critical issues affected SAP S/4HANA, SAP Landscape Transformation, and SAP Financial Consolidation, with impacts including remote code execution, authentication bypass, and potential full system compromise.
SAP released its July 2024 security patch bundle addressing 16 vulnerabilities across multiple products. The update included two high-severity flaws: CVE-2024-39592 in SAP PDCE and CVE-2024-39597 in SAP Commerce, and SAP advised immediate patching with temporary mitigations for both issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcesupport.sap.com
Open sourcecsirt.sk
Open sourcecsirt.sk
Open sourceonapsis.com
Open sourcecsirt.sk
Open sourcecsirt.sk
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.