Tuesday, September 8, 2026

SAP Patch Day Fixes Critical SQL Injection, DoS, and Code Injection Flaws

SAP released its monthly Security Patch Day updates, addressing 19 new security notes and one update to a previously released note.

According to the official SAP Support Portal, these patches resolve severe vulnerabilities, including critical SQL injection, Denial of Service (DoS), and code injection flaws.

SAP strongly advises all administrators to review these updates and apply the necessary patches immediately to protect their enterprise infrastructure.

Critical and High-Severity Flaws

The April 2026 release highlights a few pressing vulnerabilities that require immediate remediation to prevent potential threat actor exploitation. Security teams must focus on the following high-priority issues impacting core systems:

  • Critical SQL Injection (CVE-2026-27681): The most severe vulnerability patched this month affects SAP Business Planning and Consolidation and SAP Business Warehouse. Carrying a near-maximum CVSS score of 9.9, this critical SQL injection flaw could allow threat actors to execute arbitrary database queries. This could potentially lead to a complete compromise of the affected application’s confidentiality, integrity, and availability.
  • Missing Authorization Check (CVE-2026-34256): A high-severity vulnerability with a CVSS score of 7.1 was identified in SAP ERP and SAP S/4 HANA. This flaw impacts both Private Cloud and On-Premise deployments by allowing unauthorized users to perform restricted actions.

Medium-Severity Vulnerabilities

In addition to the critical patches, SAP addressed multiple medium-severity vulnerabilities across its broader product ecosystem. Converting the raw disclosure data into actionable intelligence reveals several key fixes:

  • Denial of Service in BusinessObjects: SAP BusinessObjects Business Intelligence Platform received a patch for a DoS vulnerability (CVE-2025-64775) with a CVSS score of 6.5. Exploitation could disrupt critical business analytics and reporting operations.
  • Code Injection in NetWeaver: A medium-severity code injection vulnerability (CVE-2026-27674) affecting SAP NetWeaver Application Server Java was successfully resolved.
  • Cross-Site Scripting: SAP Supplier Relationship Management contained an XSS flaw (CVE-2026-0512) that has now been mitigated to prevent client-side attacks.
  • Information Disclosure: Essential patches were released to fix information disclosure issues in SAP Human Capital Management and SAP HANA Cockpit.
  • Landscape Transformation Flaw: A low-severity code injection flaw (CVE-2026-27675) in SAP Landscape Transformation was also addressed to prevent unauthorized OS command execution.

SAP continues to emphasize the importance of timely patching to defend against evolving enterprise cyber threats. Administrators and incident response teams should prioritize the following mitigation steps:

  • Review the detailed security notes on the SAP Support Portal to understand specific version impacts.
  • Prioritize the immediate deployment of Note 3719353 to address the critical CVSS 9.9 SQL injection vulnerability.
  • Evaluate the impact of the updated November 2025 patch regarding a missing authorization check in SAP S4CORE.
  • Ensure all SAP ERP and S/4 HANA environments are updated to prevent unauthorized access and data manipulation.

Vulnerabilities Details

CVE IDDescriptionPriorityCVSS Score
CVE-2026-27681SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse Critical9.9 
CVE-2026-34256Missing Authorization check in SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) High7.1 
CVE-2025-64775Denial of Service Vulnerability in SAP BusinessObjects Business Intelligence Platform Medium6.5 
CVE-2026-34264Information Disclosure vulnerability in SAP Human Capital Management for SAP S/4HANA Medium6.5 
CVE-2026-34261Missing Authorization check in SAP Business Analytics and SAP Content Management Medium6.5 
CVE-2026-27677Missing Authorization check in SAP S/4HANA OData Service (Manage Reference Equipment) Medium6.5 
CVE-2026-27678Missing Authorization check in SAP S/4HANA Backend OData Service (Manage Reference Structures) Medium6.5 
CVE-2026-27679Missing Authorization check in SAP S/4HANA Frontend OData Service (Manage Reference Structures) Medium6.5 
CVE-2026-0512Cross-Site Scripting (XSS) vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog) Medium6.1 
CVE-2026-27674Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java) Medium6.1 
CVE-2026-34257Open Redirect vulnerability in SAP NetWeaver Application Server ABAP Medium6.1 
CVE-2026-34262Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer Medium5.0 
CVE-2026-27673Missing Authorization Check in SAP S/4HANA (Private Cloud and On-Premise) Medium4.9 
CVE-2026-27672Missing Authorization check in Material Master Application Medium4.3 
CVE-2026-27676Missing Authorization check in SAP S/4HANA OData Service (Manage Technical Object Structures) Medium4.3 
CVE-2025-42899Update: Missing Authorization check in SAP S4CORE (Manage Journal Entries) Medium4.3 
CVE-2026-24318Insecure Session Management vulnerability in SAP BusinessObjects Business Intelligence Platform Medium4.2 
CVE-2026-27683Reflected cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform Medium4.1 
CVE-2026-27680CSS Injection vulnerability in SAP NetWeaver Application Server ABAP Low3.1 
CVE-2026-27675Code Injection vulnerability in SAP Landscape Transformation Low2.0 

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells

A sophisticated Linux implant linked to compromised F5 BIG-IP...

Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data

Natural Resources Wales (NRW) has reported a personal data...

ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions

ConnectWise has announced a security issue affecting file transfer...

Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials

A large-scale phishing operation is abusing trusted Google services...

OpenAI Commits $1 Billion in Daybreak AI Cyber Tools to Protect Critical Infrastructure

OpenAI has announced a $1 billion global commitment to...

Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks

A newly analyzed Linux malware sample, dubbed Tengu, combines...

The 12 Best Wireless / Wi-Fi Security Solutions, Compared and Priced

Best value overall: Ubiquiti. Published hardware pricing, no mandatory...

The 12 Best Network Sandboxing Solutions, Compared and Priced

Best value overall: ANY.RUN. It publishes its pricing, offers...

Related Articles

Recent News