SAP released its monthly Security Patch Day updates, addressing 19 new security notes and one update to a previously released note.
According to the official SAP Support Portal, these patches resolve severe vulnerabilities, including critical SQL injection, Denial of Service (DoS), and code injection flaws.
SAP strongly advises all administrators to review these updates and apply the necessary patches immediately to protect their enterprise infrastructure.
Critical and High-Severity Flaws
The April 2026 release highlights a few pressing vulnerabilities that require immediate remediation to prevent potential threat actor exploitation. Security teams must focus on the following high-priority issues impacting core systems:
- Critical SQL Injection (CVE-2026-27681): The most severe vulnerability patched this month affects SAP Business Planning and Consolidation and SAP Business Warehouse. Carrying a near-maximum CVSS score of 9.9, this critical SQL injection flaw could allow threat actors to execute arbitrary database queries. This could potentially lead to a complete compromise of the affected application’s confidentiality, integrity, and availability.
- Missing Authorization Check (CVE-2026-34256): A high-severity vulnerability with a CVSS score of 7.1 was identified in SAP ERP and SAP S/4 HANA. This flaw impacts both Private Cloud and On-Premise deployments by allowing unauthorized users to perform restricted actions.
Medium-Severity Vulnerabilities
In addition to the critical patches, SAP addressed multiple medium-severity vulnerabilities across its broader product ecosystem. Converting the raw disclosure data into actionable intelligence reveals several key fixes:
- Denial of Service in BusinessObjects: SAP BusinessObjects Business Intelligence Platform received a patch for a DoS vulnerability (CVE-2025-64775) with a CVSS score of 6.5. Exploitation could disrupt critical business analytics and reporting operations.
- Code Injection in NetWeaver: A medium-severity code injection vulnerability (CVE-2026-27674) affecting SAP NetWeaver Application Server Java was successfully resolved.
- Cross-Site Scripting: SAP Supplier Relationship Management contained an XSS flaw (CVE-2026-0512) that has now been mitigated to prevent client-side attacks.
- Information Disclosure: Essential patches were released to fix information disclosure issues in SAP Human Capital Management and SAP HANA Cockpit.
- Landscape Transformation Flaw: A low-severity code injection flaw (CVE-2026-27675) in SAP Landscape Transformation was also addressed to prevent unauthorized OS command execution.
SAP continues to emphasize the importance of timely patching to defend against evolving enterprise cyber threats. Administrators and incident response teams should prioritize the following mitigation steps:
- Review the detailed security notes on the SAP Support Portal to understand specific version impacts.
- Prioritize the immediate deployment of Note 3719353 to address the critical CVSS 9.9 SQL injection vulnerability.
- Evaluate the impact of the updated November 2025 patch regarding a missing authorization check in SAP S4CORE.
- Ensure all SAP ERP and S/4 HANA environments are updated to prevent unauthorized access and data manipulation.
Vulnerabilities Details
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





