logo

SAP Releases Patch for Critical SQL Injection Flaw in S/4HANA

ID: be77adbf-582f-525b-be17-3f306055a2f6

STIX ID: report--be77adbf-582f-525b-be17-3f306055a2f6

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Divya

...
...

On May 12, 2026 SAP published a monthly security update fixing 15 vulnerabilities across its ecosystem — most notably CVE-2026-34260 (critical SQL injection in Enterprise Search for ABAP, CVSS 9.6) and CVE-2026-34263 (critical missing authentication in Commerce Cloud, CVSS 9.6). The advisory also addresses a high-severity OS command injection and multiple medium/low issues across NetWeaver, BusinessObjects, HANA HDI, and other components; organizations are urged to apply patches immediately to prevent data theft and remote compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.