SAP Patch Day Fixes Critical SQL Injection, DoS, and Code Injection Flaws
ID: 218b53bf-944f-50ed-ae1f-51c6a075f1b9
STIX ID: report--218b53bf-944f-50ed-ae1f-51c6a075f1b9
Feed Name: Cyber Press
SAP's April 2026 Security Patch Day released 19 new security notes and one update addressing multiple vulnerabilities, including a critical SQL injection (CVE-2026-27681, CVSS 9.9) affecting SAP Business Planning and Consolidation and SAP Business Warehouse, a missing authorization in ERP/S/4HANA (CVE-2026-34256, CVSS 7.1), and several medium/low issues across BusinessObjects, NetWeaver, SRM, HCM, and HANA Cockpit; administrators are advised to apply Security Note 3719353 and other relevant patches immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
