SAP
Vulnerabilities and patches across SAP's enterprise stack — NetWeaver Application Server (Java and ABAP), S/4HANA, Business Technology Platform, AppRouter, and Commerce Cloud — including the monthly SAP Security Patch Day cycle.
SAP Commerce Cloud Data Hub Adapter Unauthenticated RCE
Insufficient authorization checks and input validation in SAP Commerce Cloud Data Hub Adapter allow unauthenticated remote code execution. CVSS 10.0.
SAP AppRouter HTTP request smuggling in Node.js middleware
Unauthenticated HTTP request smuggling in SAP AppRouter — the Node.js middleware fronting Business Technology Platform. NVD scored it 9.1. A crafted request can desynchronize the request-response pipeline, exposing other users' responses and knocking the service offline.
SAP NetWeaver AS ABAP memory-corruption via logical errors in memory management
Authenticated memory-corruption in NetWeaver Application Server ABAP that NVD scored 9.9 — a logged-in attacker can leverage logical errors in memory management to read data, modify data, or take the application down. Fixed in the SAP July 2026 Security Patch Day.
SAP Commerce Cloud ships sample OAuth2 client with publicly documented credentials
SAP Commerce Cloud retained a sample OAuth2 client whose credentials were documented in SAP Help Portal. If left unchanged, an unauthenticated attacker can use those well-known values to obtain a valid access token and read or modify tenant data via certain APIs. NVD scored 9.1.
SAP NetWeaver Deserialization Vulnerability
SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.
SAP NetWeaver Unrestricted File Upload Vulnerability
SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.
SAP NetWeaver Directory Traversal Vulnerability
SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via a .. (dot dot) in the query string.
SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection.
SAP Multiple Products HTTP Request Smuggling Vulnerability
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.
SAP NetWeaver SQL Injection Vulnerability
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
SAP NetWeaver Information Disclosure Vulnerability
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request.
SAP NetWeaver Unrestricted File Upload Vulnerability
SAP NetWeaver contains a vulnerability that allows unrestricted file upload.
SAP NetWeaver Remote Code Execution Vulnerability
SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.
SAP NetWeaver Directory Traversal Vulnerability
SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files.
SAP NetWeaver XML External Entity (XXE) Vulnerability
SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.
SAP Customer Relationship Management (CRM) Path Traversal Vulnerability
SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.
SAP Solution Manager Missing Authentication for Critical Function Vulnerability
SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager.
SAP NetWeaver Missing Authentication for Critical Function Vulnerability
SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users.

SAP Commerce Cloud RCE Exploit Hits Days After Patch
Defused flagged active exploitation of a max-severity SAP Commerce Cloud RCE within 72 hours of patching. Unpatched instances are live targets now.

SAP Commerce Cloud CVSS 10 RCE — Patch Released
SAP patches CVE-2026-58231, a CVSS 10.0 unauthenticated RCE in Commerce Cloud's Data Hub Adapter. Apply the fix now or take the component offline.

SAP's July Patch Day: three criticals, worst is 9.9
SAP's July 2026 Security Patch Day fixes 16 flaws — three rated critical, worst a CVSS 9.9 memory-corruption bug in NetWeaver ABAP. No known exploitation yet.