Critical 9.9 Alert: SAP’s April 2026 Patch Day Targets Major SQL Injection
ID: b52a42c8-6809-5834-b190-2320952e4036
STIX ID: report--b52a42c8-6809-5834-b190-2320952e4036
Feed Name: securityonline.info
SAP's April Patch Day released 19 new security notes plus one update, led by a critical SQL Injection in SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS 9.9) that can allow authenticated users to execute crafted SQL and access/modify sensitive data. A high-severity missing-authorization issue (CVE-2026-34256, CVSS 7.1) affects ERP and S/4HANA; the release also fixes medium-severity DoS, information disclosure, XSS, OData authorization, and code injection flaws across SAP BusinessObjects, HANA, NetWeaver and related components — administrators should prioritize patching affected systems based on exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
