Cyber Security News

SAP Patches Critical SQL injection Vulnerability in SAP S/4HANA

On May 12, 2026, SAP released its highly anticipated monthly Security Patch Day updates, addressing numerous severe security flaws across its entire enterprise software portfolio.

The most alarming discovery is a critical SQL injection vulnerability in SAP S/4HANA, giving attackers a direct path to compromise core database operations.

Enterprise resource planning systems are the lifeblood of modern corporate infrastructure, and vulnerabilities of this magnitude represent a catastrophic risk to data integrity.

In total, SAP released fifteen new security notes this month, urging organizations to apply patches immediately to prevent potential network intrusions, massive data theft, and catastrophic system downtime.

Critical Threats in SAP Enterprise Systems

The defining highlight of this month’s release is SAP Security Note 3724838, which resolves a devastating SQL injection vulnerability inside the SAP Enterprise Search for Advanced Business Application Programming component of SAP S/4HANA.

Tracked as CVE-2026-34260, this critical flaw carries a near-maximum CVSS severity score of 9.6 out of 10.

If exploited, an attacker could execute malicious database queries, allowing them to read, modify, or permanently delete highly sensitive corporate financial data.

Simultaneously, SAP addressed another critical vulnerability affecting the SAP Commerce Cloud configuration.

Documented under CVE-2026-34263, with an identical CVSS score of 9.6, this missing authentication check enables external attackers to bypass security protocols entirely, leading to unauthorized system access and severe operational disruption in e-commerce.

Beyond the critical-rated flaws, the May 2026 update mitigates several high and medium-severity vulnerabilities that pose significant risks to internal enterprise networks.

SAP Security Note 3732471 patches a high-severity operating system command injection vulnerability within SAP Forecasting and Replenishment, designated as CVE-2026-34259 with a CVSS score of 8.2.

This flaw could allow a highly privileged local attacker to execute arbitrary commands on the underlying operating system, potentially paving the way for complete host takeover and lateral movement.

Furthermore, network administrators must patch a medium-severity command injection flaw in the SAP NetWeaver Application Server for ABAP, tracked as CVE-2026-40135.

Security NoteCVE IdentifierAffected SAP ProductSeverity RatingCVSS Score
3724838CVE-2026-34260SAP S/4HANA (Enterprise Search for ABAP)Critical9.6
3733064CVE-2026-34263SAP Commerce CloudCritical9.6
3732471CVE-2026-34259SAP Forecasting & ReplenishmentHigh8.2
3730019CVE-2026-40135SAP NetWeaver AS for ABAPMedium6.5
3718083CVE-2026-40133SAP S/4HANA Condition MaintenanceMedium6.3
3727717CVE-2026-40137Business Server Pages ApplicationMedium6.1
3667593CVE-2026-0502SAP BusinessObjects BI PlatformMedium5.4
3721959CVE-2026-40132SAP Strategic Enterprise ManagementMedium5.4
3716450CVE-2025-68161SAP Commerce Cloud (Apache Log4j)Medium4.8
3726583CVE-2026-34258SAPUI5 (Search UI)Medium4.7
3728690CVE-2026-27682SAP NetWeaver AS ABAPMedium4.7
3713521CVE-2026-40136SAP Financial ConsolidationMedium4.3
3718508CVE-2026-40134SAP Incentive and Commission ManagementMedium4.3
3735359CVE-2026-40129SAP Application Server ABAPMedium4.3
3726962CVE-2026-40131SAP HANA Deployment InfrastructureLow3.4

Other notable fixes include missing authorization checks across various business modules, such as SAP Strategic Enterprise Management and SAP S/4HANA Condition Maintenance.

Alongside dangerous cross-site scripting and cross-site request forgery vulnerabilities in the BusinessObjects Business Intelligence Platform.

SAP strongly recommends that all enterprise customers visit the official support portal and apply these patches on an emergency priority basis to protect their business-critical landscapes.

Delaying these crucial updates leaves environments exposed to severe exploitation, especially given the ease with which financially motivated threat actors can weaponize SQL injection and missing authentication flaws.

Security operations teams must ensure all impacted products, from SAP NetWeaver down to SAPUI5 and the SAP HANA Deployment Infrastructure deploy library, are updated to the latest secure versions to maintain a robust and impenetrable defensive posture.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.


Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

3 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

9 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

20 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

16 hours ago