SAP Security Notes & News (Security Patch Day)
sap-security-notes · A · active
https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html
Added 2026-09-29: SAP's monthly Security Patch Day summary, first-party for SAP NetWeaver / S/4HANA flaws (SAP runs finance and HR across federal and cantonal administrations). RECIPE: `extract https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html` reads the page without the reader (dated 2026-09-08 Patch Day at probe); the note bodies themselves are login-gated, so corroborate details from Onapsis / SecurityBridge write-ups. (2026-09-29 operator-directed setup review)
Cited in 3 entries
Citation cadence
Citation days per ISO week (10 weeks of coverage span, total 3).
- CVE-2026-58231, SAP Commerce Cloud: an unauthenticated request to the Data Hub Adapter import endpoint reaches arbitrary code execution (CVSS 10.0), and the fix needs a rebuild and redeploy2026-08-12
- SAP July 2026 Security Patch Day: three CVSS ≥9.1 flaws in NetWeaver AS ABAP, Approuter and Commerce Cloud, two reachable without authentication2026-07-14
- CVE-2026-44748, SAP June Patch Day: SAML XML Signature Wrapping in NetWeaver AS ABAP (CVSS 9.9) plus an unauth RFC kernel memory-corruption (CVSS 9.8)2026-06-10