Critical Alert: SAP’s Latest Security Update Fixes 9.8 CVSS RCE and Deserialization Flaws
ID: 2aefa893-6fdb-5a67-8656-18c565249df1
STIX ID: report--2aefa893-6fdb-5a67-8656-18c565249df1
Feed Name: securityonline.info
**SAP monthly security update:** SAP published 15 security notes including two Critical vulnerabilities (CVE-2019-17571 — Log4j 1.2 deserialization; CVE-2026-27685 — Insecure deserialization in NetWeaver) with CVSS scores above 9.0 that can lead to remote code execution and full system compromise; additional fixes address DoS (CVE-2026-27689), SSRF, SQL injection, XSS, and DLL hijacking across NetWeaver, Business One, and SAP GUI, and security teams are advised to prioritize the critical patches immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
