logo

SAP Patches Critical SQL Injection Flaw in SAP S/4HANA

ID: 9e3ea72f-4105-5517-bab7-725059a65dec

STIX ID: report--9e3ea72f-4105-5517-bab7-725059a65dec

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: AnuPriya

...
...

A May 2026 SAP security update addresses 15 vulnerabilities across SAP products, with two critical issues—CVE-2026-34260 (SQL injection in Enterprise Search for ABAP) and CVE-2026-34263 (missing authentication in SAP Commerce Cloud)—each rated CVSS 9.6; these flaws could enable arbitrary database queries or full bypass of authentication, risking data theft and remote compromise. The advisory also lists several other high/medium severity flaws (OS command injection, missing authorization checks, XSS, DoS, etc.) and urges immediate patching across affected SAP systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.