SAP Patches Critical SQL Injection Flaw in SAP S/4HANA
ID: 9e3ea72f-4105-5517-bab7-725059a65dec
STIX ID: report--9e3ea72f-4105-5517-bab7-725059a65dec
Feed Name: Cyber Press
A May 2026 SAP security update addresses 15 vulnerabilities across SAP products, with two critical issues—CVE-2026-34260 (SQL injection in Enterprise Search for ABAP) and CVE-2026-34263 (missing authentication in SAP Commerce Cloud)—each rated CVSS 9.6; these flaws could enable arbitrary database queries or full bypass of authentication, risking data theft and remote compromise. The advisory also lists several other high/medium severity flaws (OS command injection, missing authorization checks, XSS, DoS, etc.) and urges immediate patching across affected SAP systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
