Skip to main content
← CVE Tracker

Vendor

SAP

12 articles

CVE-2026-44747: SAP NetWeaver ABAP Out-of-Bounds Write Flaw
HIGH
Vulnerabilities

CVE-2026-44747: SAP NetWeaver ABAP Out-of-Bounds Write Flaw

SAP NetWeaver ABAP users must patch CVE-2026-44747 (CVSS 9.9) immediately to prevent authenticated attackers from exposing or modifying critical data via memory…

Runtime Rebel Intel
5 min read · Jul 14, 2026
FortiSandbox Command Injection (CVE-2026-25089) & Critical Vendor Patches
HIGH
Vulnerabilities

FortiSandbox Command Injection (CVE-2026-25089) & Critical Vendor Patches

Critical patches from Fortinet, Ivanti, and SAP address vulnerabilities including CVE-2026-25089 (FortiSandbox command injection), enabling RCE and info disclosure.

Runtime Rebel Intel
4 min read · Jun 10, 2026
VU
HIGH
Vulnerabilities

SAP NetWeaver & Commerce Cloud: Urgent Critical Patches Released

SAP addresses 15 vulnerabilities, including four critical flaws in NetWeaver AS Java and Commerce Cloud, requiring immediate patching to prevent remote exploitation.

Runtime Rebel Intel
4 min read · Jun 9, 2026
VU
HIGH
Vulnerabilities

SAP NetWeaver and Commerce CVE-2024-21733 Mitigation Guide

SAP releases January 2024 security updates addressing critical vulnerabilities in BusinessObjects, NetWeaver, and Commerce Cloud. Patch now to prevent RCE.

Runtime Rebel Intel
4 min read · Jun 9, 2026
Ivanti, Fortinet, and n8n Disclose Critical RCE and Auth Bypass Flaws
HIGH
Vulnerabilities

Ivanti, Fortinet, and n8n Disclose Critical RCE and Auth Bypass Flaws

Ivanti, Fortinet, n8n, and SAP release urgent security patches for critical vulnerabilities including CVE-2026-5444 and CVE-2026-8043. Update systems now.

Runtime Rebel Intel
3 min read · May 18, 2026
VU
HIGH
Vulnerabilities

SAP Commerce Cloud and S/4HANA Critical Vulnerabilities - Patch Now

SAP May 2024 updates address critical vulnerabilities in Commerce Cloud and S/4HANA. Learn how to mitigate RCE and SSRF risks to protect enterprise ERP systems.

Runtime Rebel Intel
4 min read · May 12, 2026
TeamPCP Targets SAP npm Packages: Mini Shai-Hulud Supply Chain Attack
HIGH
Supply Chain

TeamPCP Targets SAP npm Packages: Mini Shai-Hulud Supply Chain Attack

TeamPCP broadens supply chain attacks, compromising npm packages in SAP's cloud development ecosystem with the 'Mini Shai-Hulud' malicious code injection.

Runtime Rebel Intel
4 min read · May 1, 2026
SU
MEDIUM
Supply Chain

SAP NPM Supply Chain Attack: Analyzing the Mini Shai-Hulud Campaign

Security researchers identified a malicious supply chain attack targeting SAP via NPM packages using the Bun runtime to evade traditional EDR detection.

Runtime Rebel Intel
4 min read · Apr 30, 2026
SU
HIGH
Supply Chain

Official SAP npm Packages Compromised in TeamPCP Supply Chain Attack

Attackers compromised official SAP npm packages to exfiltrate developer credentials and tokens. Learn how to detect and remediate this supply chain threat.

Runtime Rebel Intel
4 min read · Apr 30, 2026
SAP npm Packages Compromised by “Mini Shai-Hulud” Malware
HIGH
Supply Chain

SAP npm Packages Compromised by “Mini Shai-Hulud” Malware

The Mini Shai-Hulud campaign targets SAP cloud application developers with credential-stealing npm packages. Learn how to detect and mitigate this threat.

Runtime Rebel Intel
4 min read · Apr 29, 2026
SAP CVE-2026-27681: Critical SQL Injection Vulnerability Patch Guidance
HIGH
Vulnerabilities

SAP CVE-2026-27681: Critical SQL Injection Vulnerability Patch Guidance

April Patch Tuesday addresses a critical 9.9 CVSS SQL injection vulnerability in SAP Business Warehouse and updates for Microsoft, Adobe, and Fortinet.

Runtime Rebel Intel
3 min read · Apr 15, 2026
VU
HIGH
Vulnerabilities

CVE-2024-22257: Critical SAP AS ABAP Code Injection — Patch Now

SAP releases patches for 19 vulnerabilities, including a CVSS 9.8 code injection flaw in SAP AS ABAP and high-severity RCE in SAP Business Client.

Runtime Rebel Intel
3 min read · Apr 14, 2026