SAP Patch Day Fixes Critical SQL Injection, DoS, and Code Injection Flaws
ID: 7d7f530b-0e90-5f9b-b417-44b7eaf9de0d
STIX ID: report--7d7f530b-0e90-5f9b-b417-44b7eaf9de0d
Feed Name: GBHackers
SAP's April 2026 Security Patch Day addresses 19 new security notes (plus one update), including a critical SQL injection (CVE-2026-27681, CVSS 9.9) affecting SAP Business Planning and Consolidation and SAP Business Warehouse, a high-severity missing authorization check in SAP ERP / S/4 HANA (CVE-2026-34256, CVSS 7.1), and multiple medium/low issues (DoS, code injection, XSS, information disclosure) across other SAP products; administrators are urged to review the SAP Support Portal, prioritize Note 3719353 and the relevant patches, and apply updates immediately to mitigate potential compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
