logo

SAP January 2026 Security Patch Day Fixes Critical Injection and RCE Flaws

ID: 9e09b64f-d663-5411-851d-a34f1040f7a2

STIX ID: report--9e09b64f-d663-5411-851d-a34f1040f7a2

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-01-13

Date Updated: 2026-04-22

Author: Divya

...
...

SAP published 17 security notes (January 13, 2026) addressing multiple critical and high-severity vulnerabilities across S/4HANA, Wily Introscope, HANA, NetWeaver, and Fiori apps — including a CVSS 9.9 SQL injection in General Ledger and a CVSS 9.6 RCE in Introscope — and strongly urges customers to prioritize patching and consult SAP support for remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.