Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
SAP

SAP Vendor Cyber Rating & Cyber Score

sap.com

SAP is a global leader in enterprise applications and business AI. We help organizations run mission-critical operations across finance, procurement, supply chain, human resources, and customer experience -and move from systems that record work to systems that can help execute it. The Autonomous Enterprise brings together enterprise applications, trusted business data, and AI assistants and agents that can reason, recommend, and act within business processes -with governance, accuracy, and compliance built in. • Joule: the new engagement layer, bringing together data, workflows, and agents across SAP systems and beyond. • SAP Autonomous Suite: based on AI assistants and agents executing work across all domains. • Industry AI applications


SAP A.I CyberSecurity Scoring

SAP
Company Information
Website:http://www.sap.com
Employees number:148,412
Number of followers:0
NAICS:5112
Industry Type:Software Development
Homepage:sap.com
SAP Risk Score (AI oriented)
Between 700 and 749
logo
SAPSoftware Development
Updated:
10/09/2026
738/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
SAP Global Score (TPRM)
xxxx
logo
SAPSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

SAPModerate
Current Score
738Ba (MODERATE)
01000
14 incidents
-7.43 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
740Before Incident
Cyber Attack
09 Sep 2026SAP
ReliaQuest and Florida Department of Highway Safety and Motor Vehicles: Did ShinyHunters Breach the Florida DMV Database?

ShinyHunters Breach Exposes Millions of Driver’s Licenses, SSNs, and Corporate Data in 2026 Cyberattacks

727After Incident
CRITICAL-13
FLOREL1788971139
ShinyHunters Breach Exposes Millions of Driver’s Licenses, SSNs, and Corporate Data in 2026 Cyberattacks In a series of high-profile cyberattacks in August and September 2026, the notorious hacking group ShinyHunters compromised sensitive databases, exposing millions of driver’s licenses, government IDs, and corporate records including those of deceased financier Jeffrey Epstein and targeting organizations across the U.S. and beyond. ### Key Incidents and Impact 1. Florida DMV Breach (DAVID Database) - Between 3–7 September 2026, ShinyHunters claimed to have stolen 200,000 driver records from Florida’s Driver and Vehicle Information Database (DAVID), a system used by law enforcement. - The group exploited a password-reset vulnerability to access accounts belonging to DMV employees and an FBI agent, downloading HTML and image files containing names, addresses, Social Security numbers (SSNs), birth dates, and driver’s license details. - As proof, ShinyHunters leaked Epstein’s full record, including his SSN, driver’s license ID, and vehicle registration. - The FBI’s New Orleans field office is investigating the breach, with Florida authorities yet to confirm the full extent of the compromise. 2. Nexus Dark Web Marketplace - On 1 September 2026, cybersecurity journalist Brian Krebs exposed Nexus, a dark web service selling 153 million digital scans of U.S. and Canadian driver’s licenses, along with 10 million ID cards, 3 million travel documents, and 579,000 medical cards. - The data, likely sourced from idscan.net (an identity-verification vendor under FBI investigation), included photographs, signatures, and personal details information that cannot be easily reset after exposure. - Experts warn that such data enables synthetic identity fraud, targeted phishing, and long-term identity theft, as driver’s licenses serve as a "master key" to a person’s identity. 3. Corporate and Educational Targets - ReliaQuest (22 August 2026): ShinyHunters breached the cybersecurity firm’s Okta Single Sign-On (SSO) page via a social engineering attack, posting a taunting message: "Who’s hunting who?" - RingCentral (July 2026): The cloud communications platform confirmed a breach exposing 1.6 million customer records, with ShinyHunters using fake domains to mimic legitimate company pages. - Instructure (2026): The edtech giant, which operates Canvas, paid a ransom to ShinyHunters after two breaches compromised 3.5TB of data, including student IDs, emails, and teacher-student messages. The hackers agreed to return and destroy the data, though the incident disrupted thousands of institutions in the U.S., Canada, Australia, and the UK. ### How the Attacks Unfolded ShinyHunters employed multiple tactics: - Exploiting password-reset flaws (Florida DMV, FBI agent accounts). - Social engineering (ReliaQuest, RingCentral). - Dark web marketplaces (Nexus, selling stolen IDs). - Ransomware extortion (Instructure). ### Broader Implications The breaches highlight critical vulnerabilities in identity verification systems, where driver’s licenses and government IDs once considered secure are now permanent liabilities when exposed. Unlike credit cards or passwords, biometric and personal data cannot be replaced, leaving victims vulnerable to fraud for years. As of 7 September 2026, ShinyHunters added the Florida DMV to its leak site, threatening to release more files unless contacted. The Nexus dark web service was later taken down, but the damage from these breaches remains ongoing.
INCIDENT DETAILS -
TYPE
Data BreachRansomwareDark Web Marketplace Exploitation
MOTIVATION
Financial gainData extortionIdentity theft facilitation
IMPACT
Driver’s licensesSocial Security numbers (SSNs)Government IDsCorporate recordsStudent IDsEmailsTeacher-student messagesMedical cardsVehicle registration detailsFlorida DMV’s DAVID databaseOkta SSO pagesRingCentral customer databasesInstructure’s Canvas platformidscan.net (identity-verification vendor)Disruption to thousands of educational institutionsLaw enforcement data access compromisedReliaQuestRingCentralInstructureFlorida DMVPotential regulatory finesLegal actions due to data exposureIdentity Theft Risk: High (permanent exposure of driver’s licenses and SSNs)
DATA BREACH
Driver’s licensesSocial Security numbers (SSNs)Government IDsCorporate recordsStudent IDsEmailsMedical cardsVehicle registration details200,000 (Florida DMV)153 million (Nexus)1.6 million (RingCentral)3.5TB (Instructure)Sensitivity Of Data: High (PII, biometric data, SSNs)Data Exfiltration: Yes (Nexus marketplace, ShinyHunters leaks)HTML filesImage filesNamesAddressesSSNsBirth datesDriver’s license detailsSignaturesPhotographs
AUGUST 2026
740Before Incident
Vulnerability
14 Aug 2026SAP
SAP: Critical SAP Commerce Cloud RCE Vulnerability Actively Exploited in the Wild

Critical SAP Commerce Cloud RCE Vulnerability Exploited Within Days of Patch Release

738After Incident
CRITICAL-2
SAP1786948236
Critical SAP Commerce Cloud RCE Vulnerability Exploited Within Days of Patch Release Threat intelligence provider Defused detected exploitation attempts targeting CVE-2026-58231, a critical unauthenticated remote code execution (RCE) vulnerability in SAP Commerce Cloud, just three days after SAP released its patch on August 14, 2026. The activity was observed in Defused’s honeypots, marking one of the fastest known shifts from vulnerability disclosure to in-the-wild probing for an enterprise commerce platform. The flaw, rated CVSS 10.0 (the highest severity), allows attackers to execute arbitrary commands on internet-exposed instances without authentication. Successful exploitation could enable threat actors to deploy web shells, steal credentials, exfiltrate data, stage ransomware, or move laterally within compromised networks. Despite the rapid exploitation attempts, no public proof-of-concept (PoC) exploit has been released, and the vulnerability was not previously known to be exploited. However, the incident underscores a common pattern: attackers often reverse-engineer vendor patches or adapt existing attack chains to target high-severity flaws before defenders can fully remediate them. Defused emphasized that the lack of a public PoC does not guarantee safety, as threat actors may still develop private exploits. Organizations running SAP Commerce Cloud are advised to identify affected deployments, apply SAP’s patches or mitigations, and reduce public exposure. Security teams should also monitor for abnormal activity, including unusual requests, unexpected processes, new administrative accounts, and suspicious outbound connections. While the observed activity was limited to honeypot probes rather than confirmed breaches unsuccessful scans may precede more sophisticated attacks. Defenders are encouraged to preserve logs, block malicious indicators, and conduct post-exploitation hunting to detect potential compromises. SAP and trusted threat intelligence sources should be monitored for further updates on exploitation trends.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Data Compromised: Credentials, sensitive dataSystems Affected: SAP Commerce Cloud instancesOperational Impact: Potential lateral movement, ransomware deploymentIdentity Theft Risk: High (if credentials are stolen)
DATA BREACH
Type Of Data Compromised: Credentials, sensitive dataSensitivity Of Data: HighData Exfiltration: Possible
AUGUST 2026
742Before Incident
Vulnerability
12 Aug 2026SAP
Microsoft and SAP: Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability

Microsoft and SAP Patch Critical Zero-Days in August 2026 Patch Tuesday

740After Incident
CRITICAL-2
MICSAP1786497581
Microsoft and SAP Patch Critical Zero-Days in August 2026 Patch Tuesday Microsoft’s August 2026 Patch Tuesday addressed 398 vulnerabilities, including 42 critical flaws and 355 rated Important, marking another month of heavy patch loads for security teams. Among the most urgent fixes was CVE-2026-68820, an actively exploited zero-day elevation-of-privilege vulnerability in the Windows Ancillary Function Driver (AFD) for WinSock, which handles socket commands. Researchers warned that the flaw already leveraged in the wild could be used by nation-state actors, mirroring past attacks linked to North Korean hacking groups. ### Key Vulnerabilities and Priorities 1. Actively Exploited Zero-Days - CVE-2026-68820 (WinSock Driver): Requires immediate patching due to confirmed exploitation. - CVE-2026-62832 (Windows User Profile Service): Publicly disclosed, enabling attackers to load another user’s registry hive (e.g., an admin’s) for unauthorized access. Dubbed "LegacyHive", a proof-of-concept exploit emerged hours after Patch Tuesday. 2. Critical Remote Code Execution (RCE) Flaws - Windows DNS Server RCE (CVSS 9.8) - Microsoft QUIC RCE (CVSS 9.8) - Windows iSCSI Target Service RCE (CVSS 9.8) - Windows Deployment Services TFTP Server RCE (CVSS 9.8) These vulnerabilities allow unauthenticated attackers to execute arbitrary code remotely, posing severe risks to exposed systems. 3. SharePoint and Active Directory Risks - Microsoft SharePoint Server RCE (CVSS 9.8): Assessed as highly likely to be exploited, though no active attacks were confirmed at release. - SharePoint Elevation of Privilege (EoP): Enables authenticated attackers with domain access to gain SharePoint administrator privileges. - Active Directory Certificate Services (AD CS): Highlighted for accelerated remediation due to its role in identity compromise. 4. SAP’s Critical Fixes SAP released 29 patches, including: - CVE-2026-44772 (SAP Commerce Cloud Data Hub Adapter, CVSS 10): An improper authorization flaw allowing unauthenticated attackers to execute arbitrary code via crafted data, risking data theft, application manipulation, or credential compromise. - CVE-2026-44773 (SAP NetWeaver ABAP, CVSS 9.9): A memory corruption issue in Application Server ABAP, potentially leading to system crashes or data exposure. ### Exploitation Trends and Mitigation - No workarounds exist for most critical flaws, making patch deployment the primary defense. - Systems unable to patch immediately should implement risk acceptance, segmentation, enhanced monitoring, and compensating controls. - Prioritization guidance: Focus first on actively exploited zero-days and internet-exposed systems, followed by unauthenticated RCE flaws and publicly disclosed vulnerabilities. ### Broader Context - The WinSock zero-day and SAP Commerce Cloud flaw were flagged as the highest-priority fixes this month. - SharePoint vulnerabilities were emphasized due to their potential to expose sensitive corporate data or disrupt business processes. - The sheer volume of patches (398 for Microsoft, 29 for SAP) underscores the new normal of large-scale vulnerability management, with security teams urged to triage based on exploitation status and exposure risk. The updates reflect ongoing threats from nation-state actors, ransomware groups, and opportunistic attackers, particularly targeting Windows, SharePoint, and SAP systems critical to enterprise operations.
INCIDENT DETAILS -
TYPE
Zero-Day ExploitationRemote Code ExecutionElevation of PrivilegeMemory Corruption
MOTIVATION
EspionageData TheftSystem Compromise
IMPACT
Sensitive corporate dataRegistry hivesApplication dataWindows DNS ServerMicrosoft QUICWindows iSCSI Target ServiceWindows Deployment Services TFTP ServerMicrosoft SharePoint ServerActive Directory Certificate ServicesSAP Commerce Cloud Data Hub AdapterSAP NetWeaver ABAPSystem crashesUnauthorized accessData exposureHigh (if PII exposed)
DATA BREACH
Registry hivesCorporate dataApplication dataHigh (if PII or credentials exposed)
AUGUST 2026
744Before Incident
Vulnerability
04 Aug 2026SAP
SonicWall, Citrix, Sophos, Fortinet, vBulletin, Hikvision and SAP: Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites

Russian-Speaking Hacker Linked to Global Cybercrime and Espionage Operation

742After Incident
CRITICAL-2
SAPFORVBUCITSONSOPHIK1785846368
Russian-Speaking Hacker Linked to Global Cybercrime and Espionage Operation A Russian-speaking threat actor has been identified as the orchestrator of a large-scale cyber operation targeting organizations worldwide, acting as an initial access broker (IAB) for ransomware groups. The campaign, uncovered by CloudSEK researchers, exploited exposed security appliances and unpatched vulnerabilities to breach networks across education, healthcare, financial services, telecommunications, and government sectors in over a dozen countries. ### Attack Methodology The hacker conducted large-scale scans to identify vulnerable internet-facing systems, leveraging 12 known exploits in products from Fortinet, F5, SonicWall, Sophos, Citrix, SAP, Roundcube, vBulletin, and Hikvision. Most exploits relied on public proof-of-concept (PoC) code, though some were modified for the operation. Once inside a network, the attacker: - Deployed web shells and network tunnels to move laterally. - Harvested NTLM password hashes, credential stores, and browser secrets. - Compromised Active Directory (AD), extracting Kerberos ticket-granting keys to forge long-term authentication tokens. - In some cases, achieved full domain control, enabling ransomware groups to later encrypt systems. ### Shift to Espionage: Ukraine in the Crosshairs While the initial focus was financial cybercrime, the operation later pivoted to targeting Ukrainian defense and aerospace organizations. The hacker: - Deployed Sliver command-and-control (C2) tooling. - Accessed exposed source-code repositories. - Collected hundreds of images from internet-facing IP cameras and screenshots from remote desktop sessions, likely to monitor military logistics, border crossings, and critical infrastructure. CloudSEK assessed with moderate-to-high confidence that this phase served Russian state-linked intelligence needs, though it remains unclear whether the actor was directly tasked or sold the data to a state customer. ### Shared Infrastructure and Defensive Recommendations The same VPS servers, tunnels, and tooling were used for both criminal and espionage activities, highlighting the blurred lines between cybercrime and state-sponsored operations. Organizations are advised to: - Remove administrative interfaces from direct internet exposure. - Patch vulnerable appliances immediately. - Rotate credentials and review unauthorized logins, SSH keys, and device settings. - Isolate IP cameras from public networks and replace default passwords. ### Indicators of Compromise (IoCs) CloudSEK provided key IoCs, including: - IPv4 addresses linked to operator VPS, jumpboxes, and C2 infrastructure. - SHA-256 hashes for Sliver Linux implants and malicious drivers used in credential theft. The case underscores the dual threat posed by initial access brokers facilitating both ransomware attacks and state-aligned espionage while reinforcing the risks of unpatched edge devices and exposed credentials.
INCIDENT DETAILS -
TYPE
CybercrimeEspionage
MOTIVATION
Financial gainState-aligned intelligence collection
IMPACT
Data Compromised: NTLM password hashes, credential stores, browser secrets, Kerberos ticket-granting keys, source-code repositories, images from IP cameras, remote desktop screenshotsSystems Affected: Networks across education, healthcare, financial services, telecommunications, government, defense, and aerospace sectorsOperational Impact: Full domain control achieved in some cases, enabling ransomware deploymentIdentity Theft Risk: High (due to credential harvesting)
DATA BREACH
NTLM password hashesCredential storesBrowser secretsKerberos ticket-granting keysSource-code repositoriesImages from IP camerasRemote desktop screenshotsSensitivity Of Data: High (personally identifiable information, authentication tokens, military logistics data)Data Exfiltration: Yes (data sold on dark web in some cases)ImagesSource codeScreenshotsPersonally Identifiable Information: Yes (credentials, authentication tokens)
JULY 2026
731Before Incident
JUNE 2026
733Before Incident
MAY 2026
736Before Incident
Cyber Attack
01 May 2026SAP
SAP: Red Hat npm packages compromised to steal developer credentials

Red Hat npm Packages Compromised in Supply-Chain Attack Distributing Miasma Malware

726After Incident
LOW-10
SAP1780352800
Red Hat npm Packages Compromised in Supply-Chain Attack Distributing Miasma Malware Security researchers at Aikido and OX Security uncovered a supply-chain attack targeting over 30 npm packages under Red Hat’s `@redhat-cloud-services` namespace, distributing a new variant of the Shai-Hulud credential-stealing malware, dubbed "Miasma." The compromised packages, which collectively receive 117,000 weekly downloads, were backdoored to exfiltrate sensitive data, including developer credentials, cloud secrets, SSH keys, CI/CD tokens, and environment files. Red Hat confirmed the incident, stating that the affected packages were limited to internal development tooling and were removed from the npm registry upon discovery. The company emphasized that the malicious code never reached customer-facing systems via `console.redhat.com` and that no impact on production environments or customer data has been identified. However, the root cause of the compromise including how the attacker gained access remains under investigation. The attack leveraged a compromised GitHub account belonging to a Red Hat employee, which was used to push malicious commits to multiple repositories. These commits introduced a GitHub Actions workflow that abused npm’s publishing mechanism to release backdoored versions of the packages. When installed, the packages executed a preinstall script triggering a 4.2 MB obfuscated `index.js` payload, designed to harvest credentials from AWS, Google Cloud, Azure, HashiCorp Vault, Kubernetes, npm, PyPI, Docker, GPG keys, and `.env` files. A total of 32 packages and 96 versions were affected, all under the `@redhat-cloud-services` namespace. The malware, Miasma, appears to be a modified version of the Mini Shai-Hulud framework, whose source code was leaked in May by the TeamPCP threat group. While Miasma shares core functionality with Mini Shai-Hulud such as credential theft it introduces enhanced obfuscation, multi-stage payload delivery, and expanded data exfiltration capabilities. The campaign has also compromised 309 GitHub repositories, leaving traces of the string "Miasma: The Spreading Blight" in affected code. This incident follows a recent surge in Shai-Hulud-based supply-chain attacks, which have targeted high-profile projects like Bitwarden, SAP, Mistral, TanStack, OpenAI, and GitHub. The identity of the threat actor behind this attack remains unclear whether it is TeamPCP or another group repurposing the leaked malware.
INCIDENT DETAILS -
TYPE
Supply-Chain Attack
MOTIVATION
Credential theft, data exfiltration
IMPACT
Data Compromised: Developer credentials, cloud secrets, SSH keys, CI/CD tokens, environment files, AWS/Google Cloud/Azure credentials, HashiCorp Vault secrets, Kubernetes tokens, npm/PyPI/Docker credentials, GPG keys, .env filesSystems Affected: 32 npm packages (96 versions) under @redhat-cloud-services namespace, 309 GitHub repositoriesOperational Impact: Internal development tooling compromised, no impact on customer-facing systems or production environmentsIdentity Theft Risk: High (credential theft)
DATA BREACH
Developer credentialsCloud secretsSSH keysCI/CD tokensEnvironment filesAWS/Google Cloud/Azure credentialsHashiCorp Vault secretsKubernetes tokensnpm/PyPI/Docker credentialsGPG keysSensitivity Of Data: High (credentials, secrets, keys).env files
APRIL 2026
745Before Incident
Cyber Attack
01 Apr 2026SAP
Checkmarx, Trivy and SAP: Official SAP npm packages compromised to steal credentials

SAP npm Packages Compromised in Suspected TeamPCP Supply-Chain Attack

736After Incident
CRITICAL-9
CHESAPSEC1777508710
SAP npm Packages Compromised in Suspected TeamPCP Supply-Chain Attack Security researchers have uncovered a supply-chain attack targeting multiple official SAP npm packages, believed to be orchestrated by the TeamPCP threat group. The compromise affected four packages @cap-js/sqlite (v2.2.2), @cap-js/postgres (v2.2.2), @cap-js/db-service (v2.10.1), and mbt (v1.2.48) which support SAP’s Cloud Application Programming Model (CAP) and Cloud MTA, widely used in enterprise development. The malicious packages contained a preinstall script that executed automatically upon installation, deploying a loader (setup.mjs) to fetch the Bun JavaScript runtime from GitHub. This runtime then ran an obfuscated execution.js payload, designed to steal sensitive credentials from developer systems and CI/CD environments, including: - npm and GitHub authentication tokens - SSH keys and developer credentials - Cloud credentials (AWS, Azure, Google Cloud) - Kubernetes configurations and secrets - CI/CD pipeline secrets and environment variables On CI runners, the malware used an embedded Python script to scan process memory (/proc/\<pid\>/maps and /proc/\<pid\>/mem) for secrets, bypassing log masking a tactic identical to previous TeamPCP attacks, such as those targeting Bitwarden and Checkmarx. Stolen data was encrypted and exfiltrated to public GitHub repositories under victims’ accounts, marked with the description "A Mini Shai-Hulud has Appeared" a reference mirroring the "Shai-Hulud: The Third Coming" string from earlier attacks. The malware also employed GitHub commit searches as a dead-drop mechanism, decoding commit messages containing base64-encoded tokens to escalate access. Additionally, the payload included self-propagation capabilities, using stolen credentials to modify other accessible packages and repositories, further spreading the infection. Researchers have linked the attack to TeamPCP with medium confidence, citing similarities in code and tactics to prior incidents involving Trivy, Checkmarx, and Bitwarden. While the exact compromise vector remains unclear, evidence suggests an exposed NPM token from a misconfigured CircleCI job may have been exploited. SAP has not yet responded to inquiries regarding the breach. The affected package versions have since been deprecated on npm.
INCIDENT DETAILS -
TYPE
Supply-Chain Attack
MOTIVATION
Credential theft, data exfiltration, and further propagation
IMPACT
npm and GitHub authentication tokensSSH keys and developer credentialsCloud credentials (AWS, Azure, Google Cloud)Kubernetes configurations and secretsCI/CD pipeline secrets and environment variablesSystems Affected: Developer systems and CI/CD environmentsOperational Impact: Potential unauthorized access to cloud environments and CI/CD pipelinesBrand Reputation Impact: Potential reputational damage to SAP due to compromised official packagesIdentity Theft Risk: High (stolen developer and cloud credentials)
DATA BREACH
Authentication tokensSSH keysCloud credentialsKubernetes secretsCI/CD pipeline secretsSensitivity Of Data: HighData Exfiltration: Yes (to public GitHub repositories under victims’ accounts)Data Encryption: Yes (stolen data was encrypted before exfiltration)
MARCH 2026
746Before Incident
FEBRUARY 2026
744Before Incident
JANUARY 2026
743Before Incident
DECEMBER 2025
740Before Incident
NOVEMBER 2025
739Before Incident
OCTOBER 2025
737Before Incident
SEPTEMBER 2025
746Before Incident
Cyber Attack
24 Sep 2025SAP
Jaguar Land Rover and SAP: Jaguar Land Rover failed to finish cyber insurance purchase

Jaguar Land Rover Hit by Costly Cyberattack as Insurance Gap Leaves It Exposed

732After Incident
CRITICAL-14
SAPJAG1773959105
Jaguar Land Rover Hit by Costly Cyberattack as Insurance Gap Leaves It Exposed Jaguar Land Rover (JLR), the UK’s largest automaker, is grappling with the fallout of a severe cyberattack that has forced three factories offline until at least October 1. The financial impact is estimated at £50 million ($68 million) per week, with over 30,000 employees idled and suppliers facing financial strain. The attack has been attributed to the hacking group Scattered Spider, which previously targeted British retailers, and may have exploited a vulnerability in SAP software, raising concerns about vendor governance and patch management. Unlike Marks & Spencer, which recently suffered a breach by the same group but is expected to recover over £100 million through its cyber insurance program, JLR lacks coverage. The company had been negotiating a policy through broker Lockton but failed to finalize the deal before the attack. Without insurance to offset business interruption losses, JLR is bearing the full cost of the shutdown, highlighting the risks of gaps in cyber coverage particularly for manufacturers reliant on just-in-time production and complex supply chains. The incident has sent ripples through the cyber insurance market, serving as a stress test for underwriters ahead of the autumn renewal season. It underscores the existential vulnerabilities of operating without coverage in an era of increasingly sophisticated attacks on operational technology. The shutdown has also drawn government attention, with UK industry minister Chris McDonald pledging support to stabilize JLR and its supply chain. Meanwhile, the Unite trade union has warned of potential job losses across the 104,000 roles tied to JLR’s production, and S&P Global has noted the broader economic impact in its latest UK manufacturing survey. JLR is preparing a phased restart plan, but the attack has already become a cautionary case study for enterprises on the consequences of incomplete cyber insurance placement.
INCIDENT DETAILS -
TYPE
Cyberattack
IMPACT
Financial Loss: £50 million ($68 million) per weekSystems Affected: Three factories offlineDowntime: Until at least October 1Operational Impact: 30,000 employees idled, supply chain disruption
AUGUST 2025
751Before Incident
Vulnerability
11 Aug 2025SAP
SAP

Critical SAP S/4HANA Code Injection Vulnerability (CVE-2025-42957) Exploited in the Wild

749After Incident
CRITICAL-2
SAP5464254090625
A critical SAP S/4HANA code injection vulnerability (CVE-2025-42957, CVSS 9.9) is being actively exploited in the wild, allowing low-privileged attackers to inject arbitrary ABAP code, bypass authorization, and achieve full system takeover. Despite SAP releasing a patch on August 11, 2025, unpatched systems remain exposed due to the ease of reverse-engineering the fix. Exploitation enables data theft, manipulation, privilege escalation (via backdoor accounts), credential theft, and operational disruption—including potential ransomware deployment or malware-based outages. SecurityBridge, which discovered and reported the flaw, confirmed real-world abuse, warning that skilled threat actors can weaponize it trivially. The vulnerability affects multiple SAP products, including S/4HANA (Private Cloud/On-Premise), NetWeaver ABAP, and Business One, risking enterprise-wide compromise. Administrators are urged to apply patches immediately, but delayed updates leave critical infrastructure vulnerable to full system hijacking, financial fraud, or supply-chain attacks via compromised SAP servers. The flaw’s severity stems from its ability to disrupt core business operations, expose sensitive data, and enable follow-on attacks like ransomware or lateral movement into connected networks.
INCIDENT DETAILS -
TYPE
Vulnerability ExploitationCode InjectionPrivilege EscalationUnauthorized Access
MOTIVATION
Data TheftData ManipulationPrivilege EscalationCredential TheftOperational DisruptionPotential Financial Gain
DATA BREACH
Sensitive Business DataCredentialsPotentially PIISensitivity Of Data: High
JUNE 2025
750Before Incident
Vulnerability
16 Jun 2025SAP
SAP

SAP Fixed Maximum-Severity Bug in NetWeaver (CVE-2025-42944)

748After Incident
CRITICAL-2
SAP0433304101525
SAP addressed a critical insecure deserialization vulnerability (CVE-2025-42944, CVSS 10.0) in its SAP NetWeaver platform, allowing unauthenticated attackers to execute arbitrary OS commands via malicious payloads submitted through the RMI-P4 module on an open port. Successful exploitation could fully compromise the confidentiality, integrity, and availability of the affected system, enabling attackers to take control of servers, steal sensitive data, or disrupt operations. While no in-the-wild attacks were reported, the flaw posed a severe risk to enterprises relying on NetWeaver for core business processes. Additionally, SAP patched a Directory Traversal vulnerability (CVE-2025-42937, CVSS 9.8) in SAP Print Service (SAPSprint), permitting unauthenticated attackers to overwrite system files via path traversal, and an Unrestricted File Upload flaw (CVE-2025-42910, CVSS 9.0) in SAP Supplier Relationship Management, allowing authenticated attackers to upload and execute malicious files. These vulnerabilities collectively exposed organizations to data breaches, system takeovers, and operational disruptions, particularly in supply chain and enterprise resource planning (ERP) environments.
INCIDENT DETAILS -
TYPE
Vulnerability DisclosureArbitrary Command ExecutionInsecure DeserializationDirectory TraversalUnrestricted File Upload
IMPACT
SAP NetWeaverSAP Print Service (SAPSprint)SAP Supplier Relationship ManagementOperational Impact: High (potential compromise of confidentiality, integrity, and availability)Brand Reputation Impact: Potential (due to critical vulnerabilities in enterprise software)
APRIL 2025
748Before Incident
Vulnerability
01 Apr 2025SAP
SAP

SAP NetWeaver Visual Composer Vulnerability Exploitation

746After Incident
CRITICAL-2
SAP758042625
German software giant SAP's widely-used SAP NetWeaver was exploited due to a critical vulnerability in its Visual Composer development server. The vulnerability enabled an unauthenticated attacker to upload potentially harmful executable binaries. This compromise could significantly affect the confidentiality, integrity, and availability of the targeted system. The vulnerability was detected in April 2025 and assigned the highest severity score by SAP, 10.0 (CVSS v3.1). Although SAP quickly released an emergency fix, affected systems running the latest SAP service pack were already exploited, signifying a zero-day attack.
INCIDENT DETAILS -
TYPE
Zero-day attack
IMPACT
Systems running the latest SAP service pack
MARCH 2025
787Before Incident
Breach
01 Mar 2025SAP
SAP

Inappropriate Behavior Incident Leading to CTO Departure

747After Incident
MEDIUM-40
SAP1007030425
Former CTO Jürgen Müller left SAP due to an 'incident' of inappropriate behavior at a company event, leading to an investigation into allegations of sexual harassment. Müller's departure was mutually agreed upon, and he received a compensation payout of €7.1 million ($7.5 million). The incident resulted in financial loss due to severance payments and could potentially damage SAP's reputation due to the nature of the misconduct and the public scrutiny of executive compensations.
INCIDENT DETAILS -
TYPE
Misconduct
MOTIVATION
Inappropriate behavior
IMPACT
Financial Loss: €7.1 million ($7.5 million)Brand Reputation Impact: Potential damage due to the nature of the misconduct and public scrutiny of executive compensations
JANUARY 2025
836Before Incident
Ransomware
01 Jan 2025SAP
SAP

SAP NetWeaver Visual Composer Metadata Uploader Vulnerability

785After Incident
CRITICAL-51
SAP723051525
In late April, SAP fixed a severe bug in NetWeaver Visual Composer Metadata Uploader, affecting over 1,200 instances. Multiple ransomware operators, including BianLian and RansomEXX, exploited this flaw. The bug allowed unauthenticated actors to upload malicious executables. SAP also patched a separate critical zero-day vulnerability in NetWeaver server, tracked as CVE-2025-42999, with a severity score of 9.1/10. Both vulnerabilities were abused in attacks since January 2025.
INCIDENT DETAILS -
TYPE
vulnerabilityransomware
MOTIVATION
financial gain
IMPACT
Systems Affected: over 1,200 instances
JANUARY 2019
834Before Incident
Vulnerability
01 Jan 2019SAP
SAP: SAP Releases Security Update to Patch Multiple Remote Code Execution Vulnerabilities

SAP Releases Critical Security Patches for Multiple Vulnerabilities

832After Incident
CRITICAL-2
SAP1773147083
SAP Releases Critical Security Patches for Multiple Vulnerabilities SAP has issued a security update addressing multiple vulnerabilities across its core platforms, including SAP NetWeaver, S/4HANA, Business One, Business Warehouse, and industry-specific applications. The patches resolve critical flaws that could enable remote code execution (RCE), denial-of-service (DoS), and unauthorized access if left unaddressed. ### Critical Vulnerabilities Highlighted 1. CVE-2019-17571 (CVSS 9.8) – A code injection flaw in SAP Quotation Management Insurance (FS-QUO), stemming from an Apache Log4j 1.2 deserialization issue. Unauthenticated attackers can exploit this to execute arbitrary code, compromising system confidentiality, integrity, and availability. 2. CVE-2026-27685 (CVSS 9.1) – An insecure deserialization vulnerability in SAP NetWeaver Enterprise Portal Administration, allowing highly privileged attackers to achieve RCE with cross-scope impact. 3. CVE-2026-27689 (CVSS 7.7) – A DoS vulnerability in SAP Supply Chain Management, enabling authenticated users to disrupt system availability. ### Additional Flaws Addressed - Server-Side Request Forgery (SSRF) in SAP NetWeaver AS ABAP - Missing authorization checks in NetWeaver AS ABAP, SAP BW, S/4HANA HCM (Portugal), ERP HCM (Portugal), and SAP Solution Tools Plug-In (ST-PI) - SQL injection in SAP NetWeaver Feedback Notification (CVE-2026-27684) - DOM-based XSS in SAP Business One Job Service (CVE-2026-0489) - Insecure storage protection in SAP Customer Checkout 2.0 - DLL hijacking in SAP GUI for Windows with GuiXT - DoS risk due to outdated OpenSSL in SAP NetWeaver AS Java (Adobe Document Services) ### Impact & Recommended Actions SAP advises customers to prioritize patching the FS-QUO and NetWeaver Enterprise Portal flaws, as they pose the highest risk of full system compromise. Security teams should then address remaining high and medium-severity issues, particularly in internet-facing and business-critical systems, to prevent potential lateral movement attacks via chained exploits. All fixes and implementation guidance are available via the SAP Support Portal.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)Denial-of-Service (DoS)Unauthorized AccessServer-Side Request Forgery (SSRF)SQL InjectionDOM-based XSSDLL Hijacking
IMPACT
SAP NetWeaverS/4HANABusiness OneBusiness WarehouseSAP Quotation Management Insurance (FS-QUO)SAP NetWeaver Enterprise Portal AdministrationSAP Supply Chain ManagementSAP NetWeaver AS ABAPSAP BWS/4HANA HCM (Portugal)ERP HCM (Portugal)SAP Solution Tools Plug-In (ST-PI)SAP Customer Checkout 2.0SAP GUI for Windows with GuiXTSAP NetWeaver AS Java (Adobe Document Services)System compromiseDisruption of system availabilityLateral movement attacks via chained exploits
JUNE 2017
835Before Incident
Vulnerability
16 Jun 2017SAP
SAP

SAP NetWeaver Application Server Java Directory Traversal Vulnerability

836After Incident
CRITICAL-1
SAP443032025
SAP's NetWeaver Application Server Java was found vulnerable to a critical directory traversal flaw identified as CVE-2017-12637. This vulnerability allows remote attackers to read arbitrary files, potentially leading to a compromise of sensitive information and system integrity. The flaw, given a CVSS score of 7.5, indicates a high severity risk. Being actively exploited in the wild, the Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to mitigate this risk urgently by April 9, 2025. Failure to patch or apply CISA's advisories could lead to serious data breaches, affecting customer and organizational data and disrupting significant operational capacities.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Customer dataOrganizational dataSAP NetWeaver Application Server JavaOperational Impact: Significant operational capacities disrupted
DATA BREACH
Customer dataOrganizational data

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for SAP ?
?
What was SAP's A.I Rankiteo Cyber Score in August 2026 ?
?
What was SAP's A.I Rankiteo Cyber Score in July 2026 ?
?
What was SAP's A.I Rankiteo Cyber Score in June 2026 ?
?
What was SAP's A.I Rankiteo Cyber Score in May 2026 ?
?
What was SAP's A.I Rankiteo Cyber Score in April 2026 ?
?
What was SAP's A.I Rankiteo Cyber Score in March 2026 ?
?
What was SAP's A.I Rankiteo Cyber Score in February 2026 ?
?
What was SAP's A.I Rankiteo Cyber Score in January 2026 ?
?
What was SAP's A.I Rankiteo Cyber Score in December 2025 ?
?
What was SAP's A.I Rankiteo Cyber Score in November 2025 ?
?
What was SAP's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on SAP's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with SAP ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view SAP's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?