logo

SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA

ID: 329b347f-ea44-52fa-89ce-163cba1904d5

STIX ID: report--329b347f-ea44-52fa-89ce-163cba1904d5

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Sergiu Gatlan

...
...

SAP's May 2026 security advisory fixes 15 vulnerabilities across multiple products, notably two critical flaws: a missing authentication check in SAP Commerce Cloud enabling unauthenticated server‑side code execution (CVE-2026-34263) and a SQL injection in S/4HANA allowing attackers with basic privileges to access sensitive database information (CVE-2026-34260). The advisory also addresses one high and 11 medium issues (including command injection, missing authorization checks, XSS, CSRF, and DoS); SAP reports no evidence these were exploited in the wild but the vendor notes prior supply‑chain compromises and CISA listings for past SAP vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.