
Meet the Authors
SAP Security Patch Day provides a monthly release of Security Notes addressing vulnerabilities across SAP applications, platforms, and technical layers.
Not every note carries the same risk; real exposure depends on configuration, authorization design, and how quickly vulnerabilities are prioritized and remediated.
This analysis is updated within 24 hours of each SAP Security Patch Day release, highlighting the updates most likely to affect enterprise risk and explaining how they impact operations and system exposure.
Updated August 12, 2026.
SAP Security Patch Day is a fixed point in the monthly operating cycle for SAP customers. On the second Tuesday of each month, SAP publishes Security Notes addressing vulnerabilities across core, supporting, and legacy systems.
The schedule is predictable, but the risk is not. Severity scores provide a starting point, but actual exposure depends on how a system is configured, who can access it, whether attackers can reach the vulnerability, and how quickly the issue is fixed. That challenge is compounded by gaps in public data as NIST limits CVE enrichment, while zero-day vulnerabilities can force teams to respond before patches or complete remediation guidance are available. SAPinsider’s Cybersecurity Threats and Challenges to SAP Systems 2026 benchmark research found that keeping up with SAP security notes, patches, and updates remains a leading challenge for SAP security teams.
This article provides an updated analysis of SAP Security Patch Day every month. It focuses on the issues most likely to materially affect enterprise risk, explaining why those issues matter operationally. The analysis draws on insights from SAPinsider security researchers, SAP security specialists, and trusted SAP security partners.
SAP Security Patch Day — August 2026
SAP’s August 2026 Patch Day delivered 28 new Security Notes and one GitHub security advisory, along with two updates to previously released notes. SAP listed four vulnerabilities as critical, eight as high, 17 as medium, and two as low.
Critical Issues to Prioritize
- SAP Commerce Cloud Data Hub Adapter — Improper Authorization (CVSS 10.0): An unauthenticated remote attacker could exploit insufficient authorization controls to submit malicious input and potentially execute arbitrary code, exposing data, altering system behavior, or disrupting availability.
- SAP Manufacturing Integration and Intelligence — Code Injection (CVSS 9.9): A low-privileged attacker could abuse XSL transformation processing to load attacker-controlled content and potentially execute arbitrary commands on the underlying host.
- SAP NetWeaver AS ABAP and ABAP Platform — Memory Corruption (CVSS 9.8): An unauthenticated remote attacker could send malformed DIAG protocol data that triggers memory corruption, potentially exposing sensitive information, altering system behavior, or causing an outage.
- SAP Manufacturing Integration and Intelligence — Code Injection (CVSS 9.1): A highly privileged attacker with access to the affected XSL transformation servlet could submit crafted input and potentially execute arbitrary commands on the operating system.
High-Priority Issues With Broad Reach
- SAP ABAP Developer Tools — Privilege Escalation (CVSS 8.8): A low-privileged user could use SQL Console to perform database actions beyond their assigned access, including reading or modifying sensitive data.
- SAP Commerce Cloud — Buffer Overflow in NGINX (CVSS 8.1): An unauthenticated attacker could send crafted requests that corrupt memory and, in some cases, allow arbitrary code execution.
- SAP BusinessObjects BI Platform — Credentials Disclosure (CVSS 7.9): A highly privileged attacker with local access could decrypt stored credentials and potentially use them to access other systems or data sources.
- SAP Change and Transport System Attach Tool — Remote Code Execution (CVSS 7.6): SAP updated this July 2026 note. An authenticated attacker could submit a malicious archive that, when processed, may allow arbitrary code execution.
- SAP Manufacturing Integration and Intelligence — Directory Traversal (CVSS 7.6): A privileged attacker could write files outside the intended directory, potentially affecting other applications or components on the MII host.
- SAP Manufacturing Integration and Intelligence — Missing Authorization Check (CVSS 7.3): An unauthenticated attacker could access scheduling functions and potentially view, create, change, or delete scheduling data.
- SAP Manufacturing Integration and Intelligence — Missing Authorization Check (CVSS 7.3): An unauthenticated attacker could access the affected Cost Servlet and potentially view or change application data.
- SAP Business AI Platform Approuter — Multiple Vulnerabilities (CVSS 7.0): Multiple flaws – 11 total – affect security controls in certain Approuter configurations and could expose protected resources or disrupt services.
Seventeen medium- and two low-priority entries affected common SAP application, authorization, user interface, integration, and runtime layers. Although less severe, the issues still require attention across SAP Commerce Cloud, BusinessObjects, NetWeaver, SAPUI5, S/4HANA, MII, and related components.
What Security Practitioners Are Flagging
Layer Seven Security examined how the highest-severity vulnerabilities could be exploited and what customers need to do in response. Its analysis showed that the four critical issues have very different attack requirements. It also highlighted that the two MII code-injection flaws can lead to operating-system command execution, while the ABAP memory-corruption issue requires a kernel patch.
Pathlock identified which August vulnerabilities should move to the front of the remediation queue. It singled out MII as the month’s main risk cluster – with six notes spanning critical, high, and medium severity – and argued that customers should treat them as a coordinated remediation effort. Pathlock also stressed that several fixes require follow-up work such as configuration changes, redeployments, and authorization reviews.
SecurityBridge focused on the operational work required to complete August remediation. It highlighted the additional MII configuration required after patching, the availability planning involved in an ABAP kernel update, and the configuration steps tied to Approuter. SecurityBridge also highlighted its own research contribution to the August release, a hard-coded credentials vulnerability in SAP Advanced Planning and Optimization Model Mix Planning.
SAP Security Patch Day — July 2026
SAP’s July 2026 Patch Day delivered 16 new Security Notes and one GitHub security advisory, along with three updates to previously released notes. SAP listed four vulnerabilities as critical, six as high, eight as medium, and two as low.
The critical and high-priority entries affected SAP NetWeaver AS ABAP, SAP NetWeaver AS Java, SAP Approuter, SAP Commerce Cloud, SAP Integration Suite Edge Integration Cell, SAProuter, and the Change and Transport System Attach Tool.
Critical Issues to Prioritize
- SAP NetWeaver AS ABAP — Memory Corruption (CVSS 9.9): An authenticated attacker could exploit faulty memory-management logic to perform an out-of-bounds stack write, potentially accessing or modifying data or causing system unavailability.
- SAP Approuter — HTTP Request Smuggling (CVSS 9.1): An unauthenticated remote attacker could send a crafted HTTP request that desynchronizes communications between systems, potentially exposing other users’ responses or disrupting availability in affected non-Cloud Foundry deployments.
- SAP Commerce Cloud — Insecure Sample Credentials (CVSS 9.1): An unauthenticated attacker could use publicly documented sample OAuth credentials to obtain an access token and read or modify data where the trusted client configuration was carried into production without changing its secret.
- SAP NetWeaver AS Java — Updated Directory Traversal Note (CVSS 9.0): SAP updated its June 2026 note with additional patch information. An unauthenticated remote attacker could manipulate file-inclusion parameters in a malicious HTTP logon request, potentially exposing or modifying sensitive information or making parts of the system unavailable.
High-Priority Issues With Broad Reach
- SAP Integration Suite Edge Integration Cell — Multiple Apache Camel Vulnerabilities (CVSS 8.8): Multiple Apache Camel vulnerabilities affect Edge Integration Cell versions below 8.43.11. Unlike SAP-managed Cloud Integration, customers operating Edge Integration Cell must update the runtime themselves.
- SAProuter on Microsoft Windows — DLL Hijacking (CVSS 8.4): A DLL hijacking vulnerability affects Windows-based SAProuter installations. Because SAProuter facilitates RFC traffic across SAP environments, affected customers should install the updated version and review the additional hardening measures in the note.
- SAP NetWeaver AS Java Configuration Wizard — Cross-Site Scripting (CVSS 8.2): A cross-site scripting vulnerability affects the Configuration Wizard in LMCTC 7.50, placing a technical administration component used to configure SAP NetWeaver AS Java within the July remediation scope.
- SAP Approuter — Open Redirect (CVSS 8.1): A second Approuter vulnerability could redirect users to untrusted destinations. Customers must update affected Node.js packages below version 21.2.0 and configure permitted redirect URLs strictly, a manual step that remains necessary after the software update.
- SAP Commerce Cloud — Apache Tomcat Vulnerabilities (CVSS 8.1): Multiple Apache Tomcat vulnerabilities affect SAP Commerce Cloud. Remediation instructions differ between public-cloud and on-premises deployments, making the operating model part of the applicability and update assessment.
- SAP Change and Transport System Attach Tool — Remote Code Execution (CVSS 7.6): A deserialization vulnerability in the ctsattach utility could enable remote code execution. Because the tool is obsolete and no longer available, affected organizations should identify and remove all remaining copies rather than attempt to retain it.
Eight medium- and two low-priority entries affected common SAP application, user interface, authorization, and runtime layers. Although less severe, the issues still require attention across SAP S/4HANA, NetWeaver, Fiori, and related Java components. Two were updates to June notes, requiring customers to revisit earlier assessments.
What Security Practitioners Are Flagging
Layer Seven Security examined what attackers could do and how customers can respond. Its analysis showed that the four critical issues do not create the same level or type of exposure. Some require an attacker to already have access, while others can be exploited remotely or depend on unsafe production settings. It also noted that the ABAP workaround could disrupt SAP GUI for HTML, while the NetWeaver AS Java vulnerability has no workaround.
Pathlock identified which vulnerabilities demand the fastest attention across the SAP attack surface. It gave top priority to vulnerabilities in shared ABAP, Java, routing, and Commerce components because one compromised layer could affect several applications. It also said customers should update Edge Integration Cell and strengthen related broker controls.
SecurityBridge explained why operational complexity can leave critical patches unapplied. It showed why some fixes are harder to complete, including kernel downtime, customer-managed Edge Integration Cell updates, manual Approuter configuration, and removal of the obsolete ctsattach tool. Its main point was that CVSS scores alone do not show the real risk or work involved in each fix.
SAP Security Patch Day — June 2026
SAP’s June 2026 Patch Day delivered 15 new Security Notes. SAP listed four vulnerabilities as critical, three as high, six as medium, and two as low. The critical and high-priority notes affected SAP NetWeaver AS ABAP, ABAP Platform, SAP NetWeaver AS Java, SAP Commerce Cloud, SAP Data Hub, and related authentication, RFC, web container, and middleware layers.
Critical Issues to Prioritize
- SAP NetWeaver AS ABAP and ABAP Platform — XML Signature Wrapping in SAML Authentication (CVSS 9.9): A low-privileged authenticated attacker could manipulate a signed XML or SAML message in a way that may still pass signature validation, creating risk across SSO and federated authentication paths.
- SAP NetWeaver AS ABAP and ABAP Platform — Memory Corruption (CVSS 9.8): An unauthenticated attacker could send a crafted RFC request that triggers kernel-level memory corruption, potentially affecting system confidentiality, integrity, and availability.
- SAP Commerce Cloud and SAP Data Hub — Spring Security Vulnerability (CVSS 9.1): A Spring Security issue could leave affected HTTP responses without required security headers, creating confidentiality and integrity risk in affected deployments.
- SAP NetWeaver AS Java — Directory Traversal (CVSS 9.0): An unauthenticated attacker could use path traversal in malicious HTTP logon requests, with the highest exposure where SAP NetWeaver AS Java logon endpoints are externally reachable.
High-Priority Issues With Broad Reach
- SAP Commerce Cloud — Apache Tomcat Vulnerabilities (CVSS 7.4): Multiple Apache Tomcat vulnerabilities affect SAP Commerce Cloud, adding to the dependency-related risk already present in the June Spring Security note.
- SAP NetWeaver AS ABAP and ABAP Platform — Missing Authorization Check (CVSS 7.1): A missing authorization check in ABAP report generation could allow a low-privileged user to overwrite another user’s data, creating risk where reports support financial, operational, or compliance decisions.
Several medium- and low-priority notes affected common SAP layers, including SAP S/4HANA, SAP Fiori, SAP BusinessObjects BI Platform, SAP NetWeaver AS Java, SAP Master Data Governance, ODP Data Replication APIs, and SAP Wily Introscope Enterprise Manager. While lower in severity, these issues still matter because they touch data replication, reporting, user interface, monitoring, authorization, and Java runtime paths that often sit inside broader SAP operating models.
What Security Practitioners Are Flagging
Layer Seven Security focused on the four critical June notes, emphasizing that they involve different kinds of exposure. It described the SAML issue as a trust-boundary problem in authentication, while treating the RFC memory corruption issue as especially serious because it can be triggered without authentication and requires kernel-level remediation.
Pathlock emphasized exposure-based prioritization rather than CVSS ordering. Its analysis placed the RFC memory corruption issue ahead of the higher-scored SAML issue because unauthenticated RFC-level access creates a different operational risk profile. Pathlock also highlighted the SAP NetWeaver AS Java directory traversal issue as a perimeter risk where logon endpoints are externally reachable.
SecurityBridge framed the June cycle as broader than the 15 new SAP notes. It pointed to in-between updates, including SAP Note 3747787, which SAP updated after another malicious npm package was identified in the Mini Shai-Hulud software supply chain attack. It also noted carryover updates from May involving SAP Commerce Cloud missing authentication check and SAP Forecasting & Replenishment OS command injection.
SAP Security Patch Day — May 2026
SAP’s May 2026 Patch Day delivered 15 new Security Notes. SAP listed two vulnerabilities as critical, one as high, eleven as medium, and one as low. The notes affected search, commerce, forecasting and replenishment, analytics, user interface, application server, and HANA deployment.
Critical Issues to Prioritize
- SAP S/4HANA Enterprise Search for ABAP — SQL Injection (CVSS 9.6): A SQL injection vulnerability allows a low-privileged authenticated attacker to inject malicious SQL statements through user-controlled input. Exploitation could expose sensitive database information and potentially crash the application.
- SAP Commerce Cloud — Missing Authentication Check / Code Injection (CVSS 9.6): An improper Spring Security configuration allows an unauthenticated user to upload malicious configuration and inject code. Exploitation could result in arbitrary server-side code execution with high impact to confidentiality, integrity, and availability.
High-Priority Issues With Broad Reach
- SAP Forecasting & Replenishment — OS Command Execution (CVSS 8.2): An authenticated attacker with administrative authorizations could abuse a non-remote-enabled function to execute arbitrary operating system commands. Successful exploitation could allow the attacker to read or modify system data or shut down the system, creating serious operational risk despite the elevated access required.
Several medium-priority notes affected widely deployed SAP components and shared technical layers. Issues involving Business Server Pages, SAPUI5, BusinessObjects, SAP NetWeaver AS ABAP, SAP HANA deployment tooling, and SAP Incentive and Commission Management show how lower-severity vulnerabilities can still matter when they sit inside common user interface, reporting, application server, development, or authorization paths.
What Security Practitioners Are Flagging
SecurityBridge highlighted the May release as a patch-management challenge across on-premise, cloud, and hybrid SAP environments. In addition to the 15 new notes on SAP’s Patch Day page, it listed SAP Note 3747787 on malicious open-source packages in SAP Cloud Application Programming Model and MTA Build Tool, known as the Mini Shai-Hulud malware campaign, as CVSS 10.0 to underline its importance.
Layer Seven Security focused most sharply on SAP Security Note 3747787 and the Mini Shai-Hulud npm package campaign. Its analysis described malicious SAP-related npm packages that could execute during installation, target developer, GitHub, npm, cloud, CI/CD, and service account credentials, propagate through stolen tokens, and persist through IDE and AI coding tool configuration files.
Pathlock’s analysis emphasized the operational spread of the May notes across S/4HANA search, Commerce Cloud configuration paths, forecasting and replenishment, BusinessObjects, SAPUI5, HANA deployment tooling, and developer CI/CD pipelines. Its framing pointed to SAP patching as a coordination issue across Basis, security, DevOps, Commerce Cloud, application owners, and identity teams.
MindFore connected the three Critical and High-priority notes to business-process risk across S/4HANA, Commerce Cloud, and Forecasting & Replenishment. Its comments emphasized potential exposure to sensitive business data, storefront operations, customer data, integrations, forecasting, inventory planning, and supply chain continuity.
SAP Security Patch Day — April 2026
SAP’s April 2026 Patch Day delivered 19 new Security Notes with one update. SAP listed one as critical and several as high-priority, with the remainder medium or low, affecting components across financial planning, data warehousing, ERP, and SAP S/4HANA applications.
Critical Issues to Prioritize
- SAP Business Planning and Consolidation and SAP Business Warehouse — SQL Injection (CVSS 9.9): A SQL injection vulnerability tied to authorization checks in an ABAP upload path allows low-privileged authenticated users to execute arbitrary SQL. The flaw enables direct access to planning and warehouse data, including the ability to read, modify, or delete records.
High-Priority Issues With Broad Reach
- SAP ERP and SAP S/4HANA — Missing Authorization Check (CVSS 7.1): A missing authorization check allows a low-privileged authenticated user to execute an ABAP program that can overwrite existing executable reports. If those reports are subsequently run, the intended functionality becomes unavailable, creating targeted disruption across ERP and S/4HANA business processes.
Several medium-priority notes affect widely deployed SAP components. Missing or insufficient authorization checks in SAP S/4HANA services, including OData and backend functions, illustrate how access control gaps and exposed interfaces can expand exposure across application and integration layers.
What Security Practitioners Are Flagging
SecurityBridge highlights the critical SQL injection in SAP Business Planning and Consolidation and SAP Business Warehouse as the primary risk driver, pointing to how upload-related functionality can enable unauthorized SQL execution when authorization checks are insufficient.
Pathlock’s analysis emphasizes a broader pattern of access control weaknesses, noting that multiple vulnerabilities—including those in SAP ERP and SAP S/4HANA—allow low-privileged users to affect application behavior through missing authorization checks.
Layer Seven Security similarly underscores how these issues span both database and application layers, reinforcing that authenticated access and role design remain central to exposure across SAP environments.
SAP Security Patch Day — March 2026
SAP’s March 2026 Patch Day delivered 15 new Security Notes with no updates to previous releases. SAP listed two as critical, one high-priority, and the remainder medium or low, affecting components across NetWeaver platform services and supply chain systems.
Critical Issues to Prioritize
- SAP Quotation Management Insurance (FS-QUO) — Code Injection (CVSS 9.8): A command injection vulnerability tied to an outdated Log4j dependency enables remote execution through the FS-QUO scheduler. Prioritize remediation wherever quotation scheduling services are reachable.
- SAP NetWeaver Enterprise Portal Administration — Insecure Deserialization (CVSS 9.1): An insecure deserialization flaw in Enterprise Portal Administration can allow remote code execution when malicious serialized content is processed. Address exposure where Enterprise Portal administration remains in use.
High-Priority Issues With Broad Reach
- SAP Supply Chain Management — Denial of Service (CVSS 7.7): A denial-of-service vulnerability in SAP Supply Chain Management allows excessive resource consumption through a vulnerable RFC-enabled function module. In SCM or APO planning environments, outages can cascade into logistics and manufacturing disruption.
Several medium-priority notes affect widely deployed platform layers. Server-side request forgery and missing authorization checks in SAP NetWeaver AS ABAP illustrate how configuration and exposed interfaces can expand exposure.
What Security Practitioners Are Flagging
SecurityBridge contributed research behind SAP Note 3707930, a missing authorization check in the SAP Solution Tools Plug-In (ST-PI), showing how administrative tooling can introduce exposure when authorization boundaries are weak.
Pathlock’s analysis emphasizes the operational patterns behind this month’s notes, particularly risks tied to third-party dependencies, administrative interfaces, and RFC-enabled functions. Layer Seven Security similarly highlights the Log4j dependency in FS-QUO and the Enterprise Portal deserialization flaw as examples of how vulnerabilities inside trusted services can create meaningful exposure.
SAP Security Patch Day — February 2026
SAP’s February 2026 Patch Day delivered 26 new Security Notes and one update. SAP listed two as critical, seven high-priority, 16 medium, and two low—an above normal workload with exposure concentrated in ABAP and core platform layers.
Critical Issues to Prioritize
- SAP CRM and SAP S/4HANA — Code Injection (Scripting Editor) (CVSS 9.9): A critical code injection weakness in the Scripting Editor can enable unauthorized execution of sensitive actions, including database-impacting activity in affected stacks. Prioritize wherever scripting is enabled in tightly connected landscapes.
- SAP NetWeaver AS ABAP and ABAP Platform — Missing Authorization Check (CVSS 9.6): A missing authorization check can allow background RFC activity under conditions that bypass expected controls. Remediation may extend beyond a simple transport, since SAP’s guidance includes kernel and parameter actions that can touch production behavior.
High-Priority Issues With Broad Reach
- SAP NetWeaver AS ABAP and ABAP Platform — XML Signature Wrapping (CVSS 8.8): Identity and message integrity issues deserve fast triage in landscapes that rely on signed XML workflows.
Other high-severity notes touch infrastructure shared across many SAP landscapes. Denial-of-service vulnerabilities in SAP BusinessObjects BI Platform (CVE-2026-0490 and CVE-2026-0485, both CVSS 7.5) can interrupt reporting that supports operational and regulatory activity.
What Security Practitioners Are Flagging
Several of February’s fixes trace back to work by independent researchers. Onapsis research contributed to vulnerabilities affecting the Scripting Editor and ABAP authorization behavior, showing how external research feeds directly into SAP’s remediation cycle.
Pathlock stresses that regular engagement with SAP Security Notes is central to a resilient cybersecurity posture. SecurityBridge reinforces that effective remediation depends on how patches map to real configurations, since applicability and exposure vary across landscapes.
SAP Security Patch Day — January 2026
SAP’s January 2026 Patch Day delivered 17 Security Notes, including four critical and four high-severity issues. The most consequential risks span SAP S/4HANA, monitoring, and landscape transformation systems. The remaining notes were rated medium or low.
Critical Issues to Prioritize
- SAP S/4HANA Financials — SQL Injection (CVSS 9.9): A critical SQL injection flaw can allow database manipulation under permissive RFC authorizations, directly threatening financial data integrity and reporting accuracy.
- SAP Wily Introscope Enterprise Manager — Remote Code Execution (CVSS 9.6): A remote code execution vulnerability allows arbitrary command execution on a trusted monitoring system that often runs with elevated privileges.
- SAP S/4HANA — Code Injection (CVSS 9.1): This code injection issue enables unauthorized modification of program logic and potential OS-level command execution, accelerating attacker control after initial compromise.
- SAP Landscape Transformation — Code Injection (CVSS 9.1): A code injection vulnerability allows execution logic to be altered without proper authorization checks, increasing risk in highly connected transformation environments.
What Security Practitioners Are Flagging
January’s Patch Day shows SAP security risk concentrating inside trusted systems rather than at the perimeter. Onapsis and Layer Seven Security highlight that the most severe issues rely on common enterprise conditions such as broad RFC authorizations, long-lived technical users, and embedded legacy components rather than novel exploits.
From an operational perspective, SecurityBridge notes that remediation frequently requires authorization and configuration changes alongside patching. Pathlock frames these vulnerabilities as realistic intrusion paths, where credential compromise can quickly escalate through RFC-enabled functions and trusted administrative tools.
What This Means for SAPinsiders
- Patch Day requires operational discipline. Effective Patch Day response depends on repeatable processes and clear execution. Defined ownership, severity-based triage, authorization review, and post-patch validation reduce risk without disrupting business-critical SAP operations.
- SAP security risk is structurally complex. Modern SAP environments combine core ERP, integrations, extensions, and long-lived components that expand exposure beyond individual vulnerabilities. Ongoing monitoring and informed external insight help teams understand where risk accumulates and which changes warrant attention.
- External insight reinforces internal judgment. Independent SAP security vendors provide research and early analysis that can surface exposure ahead of Patch Day. Monitoring credible vendor insight helps organizations prioritize response while retaining ownership of risk decisions.




