SAP January 2026 Security Patch Day Fixes Critical Injection and RCE Flaws
ID: 9e09b64f-d663-5411-851d-a34f1040f7a2
STIX ID: report--9e09b64f-d663-5411-851d-a34f1040f7a2
Feed Name: GBHackers
Threat Score
SAP published 17 security notes (January 13, 2026) addressing multiple critical and high-severity vulnerabilities across S/4HANA, Wily Introscope, HANA, NetWeaver, and Fiori apps — including a CVSS 9.9 SQL injection in General Ledger and a CVSS 9.6 RCE in Introscope — and strongly urges customers to prioritize patching and consult SAP support for remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
