SAP Releases Patch for Critical SQL Injection Flaw in S/4HANA
ID: be77adbf-582f-525b-be17-3f306055a2f6
STIX ID: report--be77adbf-582f-525b-be17-3f306055a2f6
Feed Name: GBHackers
On May 12, 2026 SAP published a monthly security update fixing 15 vulnerabilities across its ecosystem — most notably CVE-2026-34260 (critical SQL injection in Enterprise Search for ABAP, CVSS 9.6) and CVE-2026-34263 (critical missing authentication in Commerce Cloud, CVSS 9.6). The advisory also addresses a high-severity OS command injection and multiple medium/low issues across NetWeaver, BusinessObjects, HANA HDI, and other components; organizations are urged to apply patches immediately to prevent data theft and remote compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
