logo

Critical 9.9 Alert: SAP’s April 2026 Patch Day Targets Major SQL Injection

ID: b52a42c8-6809-5834-b190-2320952e4036

STIX ID: report--b52a42c8-6809-5834-b190-2320952e4036

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-23

Author: Ddos

...
...

SAP's April Patch Day released 19 new security notes plus one update, led by a critical SQL Injection in SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS 9.9) that can allow authenticated users to execute crafted SQL and access/modify sensitive data. A high-severity missing-authorization issue (CVE-2026-34256, CVSS 7.1) affects ERP and S/4HANA; the release also fixes medium-severity DoS, information disclosure, XSS, OData authorization, and code injection flaws across SAP BusinessObjects, HANA, NetWeaver and related components — administrators should prioritize patching affected systems based on exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.