logo

SAP Patch Day Fixes Critical SQL Injection, DoS, and Code Injection Flaws

ID: 218b53bf-944f-50ed-ae1f-51c6a075f1b9

STIX ID: report--218b53bf-944f-50ed-ae1f-51c6a075f1b9

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-04-14

Date Updated: 2026-04-14

Author: AnuPriya

...
...

SAP's April 2026 Security Patch Day released 19 new security notes and one update addressing multiple vulnerabilities, including a critical SQL injection (CVE-2026-27681, CVSS 9.9) affecting SAP Business Planning and Consolidation and SAP Business Warehouse, a missing authorization in ERP/S/4HANA (CVE-2026-34256, CVSS 7.1), and several medium/low issues across BusinessObjects, NetWeaver, SRM, HCM, and HANA Cockpit; administrators are advised to apply Security Note 3719353 and other relevant patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.