SAP vulnerabilities
31 CVEs tracked
SAP features prominently in our latest reporting with the release of 28 new and 2 updated security notes, addressing critical-severity vulnerabilities. Key themes include critical code injection and memory corruption flaws, alongside 'Missing Authorization Check' vulnerabilities across its Manufacturing (MII) and Cloud platforms. Defenders should urgently prioritize CVE-2026-58231 (a maximum-severity authorization flaw in Commerce Cloud), CVE-2026-34265 (unauthenticated DIAG protocol exploitation in NetWeaver), and CVE-2026-44765 targeting MII systems. Without immediate remediation, risks of remote code execution, sensitive data exposure, and system crashes remain high across these exposed services.
Azərbaycanca: SAP, son hesabatlarımızda kritik səviyyəli zəiflikləri aradan qaldıran geniş təhlükəsizlik yeniləmələri ilə diqqət mərkəzindədir. Əsas hadisələrə 'code injection' və 'memory corruption' boşluqları, həmçinin istehsal xətti (MII) və bulud platformalarındakı 'Missing Authorization Check' tipli zəifliklər daxildir. Müdafiəçilər təcili olaraq CVE-2026-58231 (Commerce Cloud-da maksimum ciddiyyətli icazə zəifliyi), CVE-2026-34265 (NetWeaver-da autentifikasiyasız DIAG protokolu istismarı) və MII sistemlərini hədəf alan CVE-2026-44765 kimi kritik qüsurlara diqqət yetirməlidir. Təcili tədbir görülməzsə, uzaqdan kod icrası, həssas məlumatların ifşası və sistemin sıradan çıxarılması riskləri yüksək olaraq qalır.
This vendor's CVEs31
- CVE-2026-66777EPSS 0.32%
- CVE-2026-66776EPSS 0.14%
- CVE-2026-66775EPSS 0.13%
- CVE-2026-66774EPSS 0.22%
- CVE-2026-66772EPSS 0.18%
- CVE-2026-66771EPSS 0.22%
- CVE-2026-66770EPSS 0.16%
- CVE-2026-66764EPSS 0.17%
- CVE-2026-66763EPSS 0.13%
- CVE-2026-66761EPSS 0.22%
- CVE-2026-66760EPSS 0.12%
- CVE-2026-58248EPSS 0.28%
- CVE-2026-58247EPSS 0.21%
- CVE-2026-58245EPSS 0.17%
- CVE-2026-58244EPSS 0.18%
- CVE-2026-58243EPSS 0.33%
- CVE-2026-58241EPSS 0.16%
- CVE-2026-58239EPSS 0.22%
- CVE-2026-58238EPSS 0.26%
- CVE-2026-58237EPSS 0.22%
- CVE-2026-58236EPSS 0.38%
- CVE-2026-58235EPSS 0.17%
- CVE-2026-58231EPSS 2%
- CVE-2026-58230EPSS 0.24%
- CVE-2026-44765EPSS 0.28%
- CVE-2026-44764EPSS 0.24%
- CVE-2026-44763EPSS 0.29%
- CVE-2026-44762EPSS 0.14%
- CVE-2026-44758EPSS 0.67%
- CVE-2026-40130EPSS 0.35%
- CVE-2026-34265EPSS 0.57%
This hub is built from skopnix's own reporting on SAP: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.