logo

Critical Alert: SAP’s Latest Security Update Fixes 9.8 CVSS RCE and Deserialization Flaws

ID: 2aefa893-6fdb-5a67-8656-18c565249df1

STIX ID: report--2aefa893-6fdb-5a67-8656-18c565249df1

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-10

Date Updated: 2026-04-23

Author: Ddos

...
...

**SAP monthly security update:** SAP published 15 security notes including two Critical vulnerabilities (CVE-2019-17571 — Log4j 1.2 deserialization; CVE-2026-27685 — Insecure deserialization in NetWeaver) with CVSS scores above 9.0 that can lead to remote code execution and full system compromise; additional fixes address DoS (CVE-2026-27689), SSRF, SQL injection, XSS, and DLL hijacking across NetWeaver, Business One, and SAP GUI, and security teams are advised to prioritize the critical patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.