SAP A.I CyberSecurity Scoring
SAP
Company Information
Website:http://www.sap.com
Employees number:148,412
Number of followers:0
NAICS:5112
Industry Type:Software Development
Homepage:sap.com
SAP Risk Score (AI oriented)
Between 700 and 749
SAPSoftware Development
Updated:
10/09/2026
10/09/2026
738/1000
Moderate
Ba
SAP Global Score (TPRM)
xxxx
SAPSoftware Development
Score locked

SAPModerate
Current Score
738Ba (MODERATE)
01000
14 incidents
-7.43 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
740
Cyber Attack
09 Sep 2026 • SAP
ReliaQuest and Florida Department of Highway Safety and Motor Vehicles: Did ShinyHunters Breach the Florida DMV Database?
ShinyHunters Breach Exposes Millions of Driver’s Licenses, SSNs, and Corporate Data in 2026 Cyberattacks
727
CRITICAL-13
FLOREL1788971139
ShinyHunters Breach Exposes Millions of Driver’s Licenses, SSNs, and Corporate Data in 2026 Cyberattacks
In a series of high-profile cyberattacks in August and September 2026, the notorious hacking group ShinyHunters compromised sensitive databases, exposing millions of driver’s licenses, government IDs, and corporate records including those of deceased financier Jeffrey Epstein and targeting organizations across the U.S. and beyond.
### Key Incidents and Impact
1. Florida DMV Breach (DAVID Database)
- Between 3–7 September 2026, ShinyHunters claimed to have stolen 200,000 driver records from Florida’s Driver and Vehicle Information Database (DAVID), a system used by law enforcement.
- The group exploited a password-reset vulnerability to access accounts belonging to DMV employees and an FBI agent, downloading HTML and image files containing names, addresses, Social Security numbers (SSNs), birth dates, and driver’s license details.
- As proof, ShinyHunters leaked Epstein’s full record, including his SSN, driver’s license ID, and vehicle registration.
- The FBI’s New Orleans field office is investigating the breach, with Florida authorities yet to confirm the full extent of the compromise.
2. Nexus Dark Web Marketplace
- On 1 September 2026, cybersecurity journalist Brian Krebs exposed Nexus, a dark web service selling 153 million digital scans of U.S. and Canadian driver’s licenses, along with 10 million ID cards, 3 million travel documents, and 579,000 medical cards.
- The data, likely sourced from idscan.net (an identity-verification vendor under FBI investigation), included photographs, signatures, and personal details information that cannot be easily reset after exposure.
- Experts warn that such data enables synthetic identity fraud, targeted phishing, and long-term identity theft, as driver’s licenses serve as a "master key" to a person’s identity.
3. Corporate and Educational Targets
- ReliaQuest (22 August 2026): ShinyHunters breached the cybersecurity firm’s Okta Single Sign-On (SSO) page via a social engineering attack, posting a taunting message: "Who’s hunting who?"
- RingCentral (July 2026): The cloud communications platform confirmed a breach exposing 1.6 million customer records, with ShinyHunters using fake domains to mimic legitimate company pages.
- Instructure (2026): The edtech giant, which operates Canvas, paid a ransom to ShinyHunters after two breaches compromised 3.5TB of data, including student IDs, emails, and teacher-student messages. The hackers agreed to return and destroy the data, though the incident disrupted thousands of institutions in the U.S., Canada, Australia, and the UK.
### How the Attacks Unfolded
ShinyHunters employed multiple tactics:
- Exploiting password-reset flaws (Florida DMV, FBI agent accounts).
- Social engineering (ReliaQuest, RingCentral).
- Dark web marketplaces (Nexus, selling stolen IDs).
- Ransomware extortion (Instructure).
### Broader Implications
The breaches highlight critical vulnerabilities in identity verification systems, where driver’s licenses and government IDs once considered secure are now permanent liabilities when exposed. Unlike credit cards or passwords, biometric and personal data cannot be replaced, leaving victims vulnerable to fraud for years.
As of 7 September 2026, ShinyHunters added the Florida DMV to its leak site, threatening to release more files unless contacted. The Nexus dark web service was later taken down, but the damage from these breaches remains ongoing.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
740
Vulnerability
14 Aug 2026 • SAP
SAP: Critical SAP Commerce Cloud RCE Vulnerability Actively Exploited in the Wild
Critical SAP Commerce Cloud RCE Vulnerability Exploited Within Days of Patch Release
738
CRITICAL-2
SAP1786948236
Critical SAP Commerce Cloud RCE Vulnerability Exploited Within Days of Patch Release
Threat intelligence provider Defused detected exploitation attempts targeting CVE-2026-58231, a critical unauthenticated remote code execution (RCE) vulnerability in SAP Commerce Cloud, just three days after SAP released its patch on August 14, 2026. The activity was observed in Defused’s honeypots, marking one of the fastest known shifts from vulnerability disclosure to in-the-wild probing for an enterprise commerce platform.
The flaw, rated CVSS 10.0 (the highest severity), allows attackers to execute arbitrary commands on internet-exposed instances without authentication. Successful exploitation could enable threat actors to deploy web shells, steal credentials, exfiltrate data, stage ransomware, or move laterally within compromised networks.
Despite the rapid exploitation attempts, no public proof-of-concept (PoC) exploit has been released, and the vulnerability was not previously known to be exploited. However, the incident underscores a common pattern: attackers often reverse-engineer vendor patches or adapt existing attack chains to target high-severity flaws before defenders can fully remediate them.
Defused emphasized that the lack of a public PoC does not guarantee safety, as threat actors may still develop private exploits. Organizations running SAP Commerce Cloud are advised to identify affected deployments, apply SAP’s patches or mitigations, and reduce public exposure. Security teams should also monitor for abnormal activity, including unusual requests, unexpected processes, new administrative accounts, and suspicious outbound connections.
While the observed activity was limited to honeypot probes rather than confirmed breaches unsuccessful scans may precede more sophisticated attacks. Defenders are encouraged to preserve logs, block malicious indicators, and conduct post-exploitation hunting to detect potential compromises. SAP and trusted threat intelligence sources should be monitored for further updates on exploitation trends.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
742
Vulnerability
12 Aug 2026 • SAP
Microsoft and SAP: Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability
Microsoft and SAP Patch Critical Zero-Days in August 2026 Patch Tuesday
740
CRITICAL-2
MICSAP1786497581
Microsoft and SAP Patch Critical Zero-Days in August 2026 Patch Tuesday
Microsoft’s August 2026 Patch Tuesday addressed 398 vulnerabilities, including 42 critical flaws and 355 rated Important, marking another month of heavy patch loads for security teams. Among the most urgent fixes was CVE-2026-68820, an actively exploited zero-day elevation-of-privilege vulnerability in the Windows Ancillary Function Driver (AFD) for WinSock, which handles socket commands. Researchers warned that the flaw already leveraged in the wild could be used by nation-state actors, mirroring past attacks linked to North Korean hacking groups.
### Key Vulnerabilities and Priorities
1. Actively Exploited Zero-Days
- CVE-2026-68820 (WinSock Driver): Requires immediate patching due to confirmed exploitation.
- CVE-2026-62832 (Windows User Profile Service): Publicly disclosed, enabling attackers to load another user’s registry hive (e.g., an admin’s) for unauthorized access. Dubbed "LegacyHive", a proof-of-concept exploit emerged hours after Patch Tuesday.
2. Critical Remote Code Execution (RCE) Flaws
- Windows DNS Server RCE (CVSS 9.8)
- Microsoft QUIC RCE (CVSS 9.8)
- Windows iSCSI Target Service RCE (CVSS 9.8)
- Windows Deployment Services TFTP Server RCE (CVSS 9.8)
These vulnerabilities allow unauthenticated attackers to execute arbitrary code remotely, posing severe risks to exposed systems.
3. SharePoint and Active Directory Risks
- Microsoft SharePoint Server RCE (CVSS 9.8): Assessed as highly likely to be exploited, though no active attacks were confirmed at release.
- SharePoint Elevation of Privilege (EoP): Enables authenticated attackers with domain access to gain SharePoint administrator privileges.
- Active Directory Certificate Services (AD CS): Highlighted for accelerated remediation due to its role in identity compromise.
4. SAP’s Critical Fixes
SAP released 29 patches, including:
- CVE-2026-44772 (SAP Commerce Cloud Data Hub Adapter, CVSS 10): An improper authorization flaw allowing unauthenticated attackers to execute arbitrary code via crafted data, risking data theft, application manipulation, or credential compromise.
- CVE-2026-44773 (SAP NetWeaver ABAP, CVSS 9.9): A memory corruption issue in Application Server ABAP, potentially leading to system crashes or data exposure.
### Exploitation Trends and Mitigation
- No workarounds exist for most critical flaws, making patch deployment the primary defense.
- Systems unable to patch immediately should implement risk acceptance, segmentation, enhanced monitoring, and compensating controls.
- Prioritization guidance: Focus first on actively exploited zero-days and internet-exposed systems, followed by unauthenticated RCE flaws and publicly disclosed vulnerabilities.
### Broader Context
- The WinSock zero-day and SAP Commerce Cloud flaw were flagged as the highest-priority fixes this month.
- SharePoint vulnerabilities were emphasized due to their potential to expose sensitive corporate data or disrupt business processes.
- The sheer volume of patches (398 for Microsoft, 29 for SAP) underscores the new normal of large-scale vulnerability management, with security teams urged to triage based on exploitation status and exposure risk.
The updates reflect ongoing threats from nation-state actors, ransomware groups, and opportunistic attackers, particularly targeting Windows, SharePoint, and SAP systems critical to enterprise operations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
744
Vulnerability
04 Aug 2026 • SAP
SonicWall, Citrix, Sophos, Fortinet, vBulletin, Hikvision and SAP: Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites
Russian-Speaking Hacker Linked to Global Cybercrime and Espionage Operation
742
CRITICAL-2
SAPFORVBUCITSONSOPHIK1785846368
Russian-Speaking Hacker Linked to Global Cybercrime and Espionage Operation
A Russian-speaking threat actor has been identified as the orchestrator of a large-scale cyber operation targeting organizations worldwide, acting as an initial access broker (IAB) for ransomware groups. The campaign, uncovered by CloudSEK researchers, exploited exposed security appliances and unpatched vulnerabilities to breach networks across education, healthcare, financial services, telecommunications, and government sectors in over a dozen countries.
### Attack Methodology
The hacker conducted large-scale scans to identify vulnerable internet-facing systems, leveraging 12 known exploits in products from Fortinet, F5, SonicWall, Sophos, Citrix, SAP, Roundcube, vBulletin, and Hikvision. Most exploits relied on public proof-of-concept (PoC) code, though some were modified for the operation.
Once inside a network, the attacker:
- Deployed web shells and network tunnels to move laterally.
- Harvested NTLM password hashes, credential stores, and browser secrets.
- Compromised Active Directory (AD), extracting Kerberos ticket-granting keys to forge long-term authentication tokens.
- In some cases, achieved full domain control, enabling ransomware groups to later encrypt systems.
### Shift to Espionage: Ukraine in the Crosshairs
While the initial focus was financial cybercrime, the operation later pivoted to targeting Ukrainian defense and aerospace organizations. The hacker:
- Deployed Sliver command-and-control (C2) tooling.
- Accessed exposed source-code repositories.
- Collected hundreds of images from internet-facing IP cameras and screenshots from remote desktop sessions, likely to monitor military logistics, border crossings, and critical infrastructure.
CloudSEK assessed with moderate-to-high confidence that this phase served Russian state-linked intelligence needs, though it remains unclear whether the actor was directly tasked or sold the data to a state customer.
### Shared Infrastructure and Defensive Recommendations
The same VPS servers, tunnels, and tooling were used for both criminal and espionage activities, highlighting the blurred lines between cybercrime and state-sponsored operations. Organizations are advised to:
- Remove administrative interfaces from direct internet exposure.
- Patch vulnerable appliances immediately.
- Rotate credentials and review unauthorized logins, SSH keys, and device settings.
- Isolate IP cameras from public networks and replace default passwords.
### Indicators of Compromise (IoCs)
CloudSEK provided key IoCs, including:
- IPv4 addresses linked to operator VPS, jumpboxes, and C2 infrastructure.
- SHA-256 hashes for Sliver Linux implants and malicious drivers used in credential theft.
The case underscores the dual threat posed by initial access brokers facilitating both ransomware attacks and state-aligned espionage while reinforcing the risks of unpatched edge devices and exposed credentials.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
731
JUNE 2026
733
MAY 2026
736
Cyber Attack
01 May 2026 • SAP
SAP: Red Hat npm packages compromised to steal developer credentials
Red Hat npm Packages Compromised in Supply-Chain Attack Distributing Miasma Malware
726
LOW-10
SAP1780352800
Red Hat npm Packages Compromised in Supply-Chain Attack Distributing Miasma Malware
Security researchers at Aikido and OX Security uncovered a supply-chain attack targeting over 30 npm packages under Red Hat’s `@redhat-cloud-services` namespace, distributing a new variant of the Shai-Hulud credential-stealing malware, dubbed "Miasma." The compromised packages, which collectively receive 117,000 weekly downloads, were backdoored to exfiltrate sensitive data, including developer credentials, cloud secrets, SSH keys, CI/CD tokens, and environment files.
Red Hat confirmed the incident, stating that the affected packages were limited to internal development tooling and were removed from the npm registry upon discovery. The company emphasized that the malicious code never reached customer-facing systems via `console.redhat.com` and that no impact on production environments or customer data has been identified. However, the root cause of the compromise including how the attacker gained access remains under investigation.
The attack leveraged a compromised GitHub account belonging to a Red Hat employee, which was used to push malicious commits to multiple repositories. These commits introduced a GitHub Actions workflow that abused npm’s publishing mechanism to release backdoored versions of the packages. When installed, the packages executed a preinstall script triggering a 4.2 MB obfuscated `index.js` payload, designed to harvest credentials from AWS, Google Cloud, Azure, HashiCorp Vault, Kubernetes, npm, PyPI, Docker, GPG keys, and `.env` files.
A total of 32 packages and 96 versions were affected, all under the `@redhat-cloud-services` namespace. The malware, Miasma, appears to be a modified version of the Mini Shai-Hulud framework, whose source code was leaked in May by the TeamPCP threat group. While Miasma shares core functionality with Mini Shai-Hulud such as credential theft it introduces enhanced obfuscation, multi-stage payload delivery, and expanded data exfiltration capabilities. The campaign has also compromised 309 GitHub repositories, leaving traces of the string "Miasma: The Spreading Blight" in affected code.
This incident follows a recent surge in Shai-Hulud-based supply-chain attacks, which have targeted high-profile projects like Bitwarden, SAP, Mistral, TanStack, OpenAI, and GitHub. The identity of the threat actor behind this attack remains unclear whether it is TeamPCP or another group repurposing the leaked malware.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
745
Cyber Attack
01 Apr 2026 • SAP
Checkmarx, Trivy and SAP: Official SAP npm packages compromised to steal credentials
SAP npm Packages Compromised in Suspected TeamPCP Supply-Chain Attack
736
CRITICAL-9
CHESAPSEC1777508710
SAP npm Packages Compromised in Suspected TeamPCP Supply-Chain Attack
Security researchers have uncovered a supply-chain attack targeting multiple official SAP npm packages, believed to be orchestrated by the TeamPCP threat group. The compromise affected four packages @cap-js/sqlite (v2.2.2), @cap-js/postgres (v2.2.2), @cap-js/db-service (v2.10.1), and mbt (v1.2.48) which support SAP’s Cloud Application Programming Model (CAP) and Cloud MTA, widely used in enterprise development.
The malicious packages contained a preinstall script that executed automatically upon installation, deploying a loader (setup.mjs) to fetch the Bun JavaScript runtime from GitHub. This runtime then ran an obfuscated execution.js payload, designed to steal sensitive credentials from developer systems and CI/CD environments, including:
- npm and GitHub authentication tokens
- SSH keys and developer credentials
- Cloud credentials (AWS, Azure, Google Cloud)
- Kubernetes configurations and secrets
- CI/CD pipeline secrets and environment variables
On CI runners, the malware used an embedded Python script to scan process memory (/proc/\<pid\>/maps and /proc/\<pid\>/mem) for secrets, bypassing log masking a tactic identical to previous TeamPCP attacks, such as those targeting Bitwarden and Checkmarx.
Stolen data was encrypted and exfiltrated to public GitHub repositories under victims’ accounts, marked with the description "A Mini Shai-Hulud has Appeared" a reference mirroring the "Shai-Hulud: The Third Coming" string from earlier attacks. The malware also employed GitHub commit searches as a dead-drop mechanism, decoding commit messages containing base64-encoded tokens to escalate access.
Additionally, the payload included self-propagation capabilities, using stolen credentials to modify other accessible packages and repositories, further spreading the infection.
Researchers have linked the attack to TeamPCP with medium confidence, citing similarities in code and tactics to prior incidents involving Trivy, Checkmarx, and Bitwarden. While the exact compromise vector remains unclear, evidence suggests an exposed NPM token from a misconfigured CircleCI job may have been exploited.
SAP has not yet responded to inquiries regarding the breach. The affected package versions have since been deprecated on npm.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
746
FEBRUARY 2026
744
JANUARY 2026
743
DECEMBER 2025
740
NOVEMBER 2025
739
OCTOBER 2025
737
SEPTEMBER 2025
746
Cyber Attack
24 Sep 2025 • SAP
Jaguar Land Rover and SAP: Jaguar Land Rover failed to finish cyber insurance purchase
Jaguar Land Rover Hit by Costly Cyberattack as Insurance Gap Leaves It Exposed
732
CRITICAL-14
SAPJAG1773959105
Jaguar Land Rover Hit by Costly Cyberattack as Insurance Gap Leaves It Exposed
Jaguar Land Rover (JLR), the UK’s largest automaker, is grappling with the fallout of a severe cyberattack that has forced three factories offline until at least October 1. The financial impact is estimated at £50 million ($68 million) per week, with over 30,000 employees idled and suppliers facing financial strain. The attack has been attributed to the hacking group Scattered Spider, which previously targeted British retailers, and may have exploited a vulnerability in SAP software, raising concerns about vendor governance and patch management.
Unlike Marks & Spencer, which recently suffered a breach by the same group but is expected to recover over £100 million through its cyber insurance program, JLR lacks coverage. The company had been negotiating a policy through broker Lockton but failed to finalize the deal before the attack. Without insurance to offset business interruption losses, JLR is bearing the full cost of the shutdown, highlighting the risks of gaps in cyber coverage particularly for manufacturers reliant on just-in-time production and complex supply chains.
The incident has sent ripples through the cyber insurance market, serving as a stress test for underwriters ahead of the autumn renewal season. It underscores the existential vulnerabilities of operating without coverage in an era of increasingly sophisticated attacks on operational technology. The shutdown has also drawn government attention, with UK industry minister Chris McDonald pledging support to stabilize JLR and its supply chain. Meanwhile, the Unite trade union has warned of potential job losses across the 104,000 roles tied to JLR’s production, and S&P Global has noted the broader economic impact in its latest UK manufacturing survey.
JLR is preparing a phased restart plan, but the attack has already become a cautionary case study for enterprises on the consequences of incomplete cyber insurance placement.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
AUGUST 2025
751
Vulnerability
11 Aug 2025 • SAP
SAP
Critical SAP S/4HANA Code Injection Vulnerability (CVE-2025-42957) Exploited in the Wild
749
CRITICAL-2
SAP5464254090625
A critical SAP S/4HANA code injection vulnerability (CVE-2025-42957, CVSS 9.9) is being actively exploited in the wild, allowing low-privileged attackers to inject arbitrary ABAP code, bypass authorization, and achieve full system takeover. Despite SAP releasing a patch on August 11, 2025, unpatched systems remain exposed due to the ease of reverse-engineering the fix. Exploitation enables data theft, manipulation, privilege escalation (via backdoor accounts), credential theft, and operational disruption—including potential ransomware deployment or malware-based outages. SecurityBridge, which discovered and reported the flaw, confirmed real-world abuse, warning that skilled threat actors can weaponize it trivially. The vulnerability affects multiple SAP products, including S/4HANA (Private Cloud/On-Premise), NetWeaver ABAP, and Business One, risking enterprise-wide compromise. Administrators are urged to apply patches immediately, but delayed updates leave critical infrastructure vulnerable to full system hijacking, financial fraud, or supply-chain attacks via compromised SAP servers. The flaw’s severity stems from its ability to disrupt core business operations, expose sensitive data, and enable follow-on attacks like ransomware or lateral movement into connected networks.
INCIDENT DETAILS -
TYPE
MOTIVATION
DATA BREACH
REFERENCES
JUNE 2025
750
Vulnerability
16 Jun 2025 • SAP
SAP
SAP Fixed Maximum-Severity Bug in NetWeaver (CVE-2025-42944)
748
CRITICAL-2
SAP0433304101525
SAP addressed a critical insecure deserialization vulnerability (CVE-2025-42944, CVSS 10.0) in its SAP NetWeaver platform, allowing unauthenticated attackers to execute arbitrary OS commands via malicious payloads submitted through the RMI-P4 module on an open port. Successful exploitation could fully compromise the confidentiality, integrity, and availability of the affected system, enabling attackers to take control of servers, steal sensitive data, or disrupt operations. While no in-the-wild attacks were reported, the flaw posed a severe risk to enterprises relying on NetWeaver for core business processes. Additionally, SAP patched a Directory Traversal vulnerability (CVE-2025-42937, CVSS 9.8) in SAP Print Service (SAPSprint), permitting unauthenticated attackers to overwrite system files via path traversal, and an Unrestricted File Upload flaw (CVE-2025-42910, CVSS 9.0) in SAP Supplier Relationship Management, allowing authenticated attackers to upload and execute malicious files. These vulnerabilities collectively exposed organizations to data breaches, system takeovers, and operational disruptions, particularly in supply chain and enterprise resource planning (ERP) environments.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
APRIL 2025
748
Vulnerability
01 Apr 2025 • SAP
SAP
SAP NetWeaver Visual Composer Vulnerability Exploitation
746
CRITICAL-2
SAP758042625
German software giant SAP's widely-used SAP NetWeaver was exploited due to a critical vulnerability in its Visual Composer development server. The vulnerability enabled an unauthenticated attacker to upload potentially harmful executable binaries. This compromise could significantly affect the confidentiality, integrity, and availability of the targeted system. The vulnerability was detected in April 2025 and assigned the highest severity score by SAP, 10.0 (CVSS v3.1). Although SAP quickly released an emergency fix, affected systems running the latest SAP service pack were already exploited, signifying a zero-day attack.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
MARCH 2025
787
Breach
01 Mar 2025 • SAP
SAP
Inappropriate Behavior Incident Leading to CTO Departure
747
MEDIUM-40
SAP1007030425
Former CTO Jürgen Müller left SAP due to an 'incident' of inappropriate behavior at a company event, leading to an investigation into allegations of sexual harassment. Müller's departure was mutually agreed upon, and he received a compensation payout of €7.1 million ($7.5 million). The incident resulted in financial loss due to severance payments and could potentially damage SAP's reputation due to the nature of the misconduct and the public scrutiny of executive compensations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
JANUARY 2025
836
Ransomware
01 Jan 2025 • SAP
SAP
SAP NetWeaver Visual Composer Metadata Uploader Vulnerability
785
CRITICAL-51
SAP723051525
In late April, SAP fixed a severe bug in NetWeaver Visual Composer Metadata Uploader, affecting over 1,200 instances. Multiple ransomware operators, including BianLian and RansomEXX, exploited this flaw. The bug allowed unauthenticated actors to upload malicious executables. SAP also patched a separate critical zero-day vulnerability in NetWeaver server, tracked as CVE-2025-42999, with a severity score of 9.1/10. Both vulnerabilities were abused in attacks since January 2025.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
JANUARY 2019
834
Vulnerability
01 Jan 2019 • SAP
SAP: SAP Releases Security Update to Patch Multiple Remote Code Execution Vulnerabilities
SAP Releases Critical Security Patches for Multiple Vulnerabilities
832
CRITICAL-2
SAP1773147083
SAP Releases Critical Security Patches for Multiple Vulnerabilities
SAP has issued a security update addressing multiple vulnerabilities across its core platforms, including SAP NetWeaver, S/4HANA, Business One, Business Warehouse, and industry-specific applications. The patches resolve critical flaws that could enable remote code execution (RCE), denial-of-service (DoS), and unauthorized access if left unaddressed.
### Critical Vulnerabilities Highlighted
1. CVE-2019-17571 (CVSS 9.8) – A code injection flaw in SAP Quotation Management Insurance (FS-QUO), stemming from an Apache Log4j 1.2 deserialization issue. Unauthenticated attackers can exploit this to execute arbitrary code, compromising system confidentiality, integrity, and availability.
2. CVE-2026-27685 (CVSS 9.1) – An insecure deserialization vulnerability in SAP NetWeaver Enterprise Portal Administration, allowing highly privileged attackers to achieve RCE with cross-scope impact.
3. CVE-2026-27689 (CVSS 7.7) – A DoS vulnerability in SAP Supply Chain Management, enabling authenticated users to disrupt system availability.
### Additional Flaws Addressed
- Server-Side Request Forgery (SSRF) in SAP NetWeaver AS ABAP
- Missing authorization checks in NetWeaver AS ABAP, SAP BW, S/4HANA HCM (Portugal), ERP HCM (Portugal), and SAP Solution Tools Plug-In (ST-PI)
- SQL injection in SAP NetWeaver Feedback Notification (CVE-2026-27684)
- DOM-based XSS in SAP Business One Job Service (CVE-2026-0489)
- Insecure storage protection in SAP Customer Checkout 2.0
- DLL hijacking in SAP GUI for Windows with GuiXT
- DoS risk due to outdated OpenSSL in SAP NetWeaver AS Java (Adobe Document Services)
### Impact & Recommended Actions
SAP advises customers to prioritize patching the FS-QUO and NetWeaver Enterprise Portal flaws, as they pose the highest risk of full system compromise. Security teams should then address remaining high and medium-severity issues, particularly in internet-facing and business-critical systems, to prevent potential lateral movement attacks via chained exploits.
All fixes and implementation guidance are available via the SAP Support Portal.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JUNE 2017
835
Vulnerability
16 Jun 2017 • SAP
SAP
SAP NetWeaver Application Server Java Directory Traversal Vulnerability
836
CRITICAL-1
SAP443032025
SAP's NetWeaver Application Server Java was found vulnerable to a critical directory traversal flaw identified as CVE-2017-12637. This vulnerability allows remote attackers to read arbitrary files, potentially leading to a compromise of sensitive information and system integrity. The flaw, given a CVSS score of 7.5, indicates a high severity risk. Being actively exploited in the wild, the Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to mitigate this risk urgently by April 9, 2025. Failure to patch or apply CISA's advisories could lead to serious data breaches, affecting customer and organizational data and disrupting significant operational capacities.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for SAP ??
What was SAP's A.I Rankiteo Cyber Score in August 2026 ??
What was SAP's A.I Rankiteo Cyber Score in July 2026 ??
What was SAP's A.I Rankiteo Cyber Score in June 2026 ??
What was SAP's A.I Rankiteo Cyber Score in May 2026 ??
What was SAP's A.I Rankiteo Cyber Score in April 2026 ??
What was SAP's A.I Rankiteo Cyber Score in March 2026 ??
What was SAP's A.I Rankiteo Cyber Score in February 2026 ??
What was SAP's A.I Rankiteo Cyber Score in January 2026 ??
What was SAP's A.I Rankiteo Cyber Score in December 2025 ??
What was SAP's A.I Rankiteo Cyber Score in November 2025 ??
What was SAP's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on SAP's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with SAP ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view SAP's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?