logo

Critical SAP Alert: S/4HANA SQL Injection & Wily RCE Threaten Financial Data

ID: 5e7627fb-0996-5f3d-b18d-19a89aede226

STIX ID: report--5e7627fb-0996-5f3d-b18d-19a89aede226

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-01-14

Date Updated: 2026-04-23

Author: Ddos

...
...

SAP issued 17 security notes on 2026-01-13 addressing multiple critical and high-severity flaws—notably CVE-2026-0501 (SQL injection, CVSS 9.9) in S/4HANA and CVE-2026-0500 (unauthenticated RCE, CVSS 9.6) in Wily Introscope—that can enable data exfiltration, arbitrary code execution, and full system compromise; organizations are strongly urged to apply the patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.