Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SAP Security Patch Day – May 2026

SAP has released its May 2026 security patch package containing 15 security notes addressing vulnerabilities across enterprise SAP environments. This release includes two HotNews vulnerabilities with CVSS ratings up to 9.6, one High priority issue, eleven Medium priority fixes, and one Low priority update. The patches affect SAP Commerce Cloud, SAP S/4HANA, SAP NetWeaver Application Server ABAP, SAP HANA, SAP Forecasting & Replenishment, SAP BusinessObjects BI Platform, and other application components.

Total Security Notes
15
HotNews Critical
2
High Priority
1
Medium Priority
11
Low Priority
1

Executive Summary

  • Critical Missing Authentication Check: CVE-2026-34263 (CVSS 9.6) in SAP Commerce Cloud configuration allows unauthenticated attackers to bypass authentication and achieve full compromise of confidentiality, integrity, and availability with cross-scope impact.
  • Critical SQL Injection: CVE-2026-34260 (CVSS 9.6) in SAP S/4HANA (SAP Enterprise Search for ABAP) enables authenticated attackers to inject malicious SQL statements, leading to cross-scope compromise with high impact on confidentiality and availability.
  • High Severity OS Command Injection: CVE-2026-34259 (CVSS 8.2) in SAP Forecasting & Replenishment allows high-privileged attackers to execute arbitrary OS commands with cross-scope impact on confidentiality, integrity, and availability.
  • OS Command Injection in NetWeaver: CVE-2026-40135 (CVSS 6.5) in SAP NetWeaver Application Server for ABAP and ABAP Platform enables high-privileged authenticated attackers to compromise integrity and availability of the application server.

Critical HotNews Vulnerabilities

Missing Authentication Check in SAP Commerce Cloud Configuration

9.6 CVE-2026-34263 CEC-SCC-CDM-BO-APP Missing Authentication
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Critical missing authentication check in SAP Commerce Cloud configuration allows unauthenticated remote attackers to bypass authentication controls. Successful exploitation results in cross-scope impact with complete compromise of confidentiality, integrity, and availability of the Commerce Cloud environment.

SAP Note 3733064 — emergency patch required immediately.

SQL Injection Vulnerability in SAP S/4HANA (SAP Enterprise Search for ABAP)

9.6 CVE-2026-34260 BC-EIM-ESH SQL Injection
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H

Critical SQL injection vulnerability in SAP S/4HANA (SAP Enterprise Search for ABAP) allows authenticated attackers to inject malicious SQL statements. Successful exploitation leads to cross-scope impact with full compromise of confidentiality and availability of business-critical data.

SAP Note 3724838 — patch within 24 hours.

High Priority Security Issues

OS Command Injection Vulnerability in SAP Forecasting & Replenishment

8.2 CVE-2026-34259 SCM-FRE-FRP OS Command Injection
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

OS command injection vulnerability in SAP Forecasting & Replenishment allows high-privileged local attackers to execute arbitrary operating system commands. Successful exploitation results in cross-scope impact with complete compromise of confidentiality, integrity, and availability of the host system.

SAP Note 3732471 — apply high priority patch.

Medium Priority Vulnerabilities

OS Command Injection in SAP NetWeaver Application Server for ABAP and ABAP Platform

6.5 CVE-2026-40135 BC-ABA-SC OS Command Injection
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

OS command injection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform allows high-privileged authenticated attackers to execute arbitrary OS commands with high impact on integrity and availability of the application server.

SAP Note 3730019 — schedule patch.

Missing Authorization Check in SAP S/4HANA Condition Maintenance

6.3 CVE-2026-40133 SD-MD-CM Missing Auth
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Missing authorization check in SAP S/4HANA Condition Maintenance allows authenticated attackers to bypass authorization controls with low impact on confidentiality, integrity, and availability of condition master data.

SAP Note 3718083 — schedule patch.

Cross-Site Scripting (XSS) in Business Server Pages Application (TAF_APPLAUNCHER)

6.1 CVE-2026-40137 SV-SMG-TWB-CBT XSS
CVSS:/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Cross-Site Scripting vulnerability in Business Server Pages Application (TAF_APPLAUNCHER) allows unauthenticated attackers to inject malicious scripts that execute in victim browsers, leading to cross-scope impact on confidentiality and integrity when users interact with crafted content.

SAP Note 3727717 — schedule patch.

Missing Authorization Check in SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard)

5.4 CVE-2026-40132 FIN-SEM-CPM-BSC Missing Auth
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Missing authorization check in SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard) allows authenticated attackers to bypass authorization controls with low impact on confidentiality and integrity of strategic enterprise data.

SAP Note 3721959 — apply update.

Cross Site Request Forgery (CSRF) in SAP BusinessObjects Business Intelligence Platform

5.4 CVE-2026-0502 BI-BIP-INV CSRF
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

Cross Site Request Forgery vulnerability in SAP BusinessObjects Business Intelligence Platform allows unauthenticated attackers to trick authenticated users into performing unintended actions, leading to low impact on integrity and availability of BI reports and platform resources.

SAP Note 3667593 — schedule patch.

Improper Certificate Validation in SAP Commerce Cloud (Apache Log4j)

4.8 CVE-2025-68161 CEC-SCC-PLA-PL Cert Validation
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Potential improper certificate validation in SAP Commerce Cloud stemming from Apache Log4j allows unauthenticated attackers under complex conditions to bypass certificate trust checks with low impact on confidentiality and integrity.

SAP Note 3716450 — schedule update.

Reflected Cross-Site Scripting (XSS) in SAP NetWeaver Application Server ABAP (BSP Applications)

4.7 CVE-2026-27682 BC-BSP Reflected XSS
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

Reflected Cross-Site Scripting vulnerability in applications based on Business Server Pages within SAP NetWeaver Application Server ABAP allows unauthenticated attackers under complex conditions to inject scripts that execute in victim browsers, with cross-scope impact on confidentiality and integrity.

SAP Note 3728690 — apply patch.

Content Spoofing Vulnerability in SAPUI5 (Search UI)

4.7 CVE-2026-34258 HAN-AS-INA-UI Content Spoofing
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

Content spoofing vulnerability in SAPUI5 (Search UI) allows unauthenticated attackers to manipulate displayed content and mislead end users, with cross-scope impact on confidentiality when victims interact with crafted UI content.

SAP Note 3726583 — schedule update.

Code Injection in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform

4.3 CVE-2026-40129 BC-MID-ICF Code Injection
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Code injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform allows authenticated attackers to inject limited code constructs into the runtime with low impact on integrity of the application server.

SAP Note 3735359 — apply fix.

Denial of Service (DoS) in SAP Financial Consolidation

4.3 CVE-2026-40136 EPM-BFC-PSI DoS
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Denial of service vulnerability in SAP Financial Consolidation allows authenticated attackers to disrupt service availability with low impact on availability of consolidation and financial reporting processes.

SAP Note 3713521 — routine update.

Missing Authorization Check in SAP Incentive and Commission Management

4.3 CVE-2026-40134 ICM Missing Auth
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Missing authorization check in SAP Incentive and Commission Management allows authenticated attackers to bypass authorization controls with low impact on integrity of incentive and commission data.

SAP Note 3718508 — apply update.

Low Priority Security Updates

SQL Injection Vulnerability in SAP HANA Deployment Infrastructure (HDI) deploy Library

3.4 CVE-2026-40131 HAN-DB-DI SQL Injection
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L

SQL injection vulnerability in the SAP HANA Deployment Infrastructure (HDI) deploy library allows local high-privileged attackers to inject limited SQL statements with low impact on confidentiality and availability of HDI deployments.

SAP Note 3726962 — regular maintenance cycle.

Explore More

SAP Security Patch Day – March 2026

SAP has released its March 2026 security patch package containing 15 security notes addressing vulnerabilities across enterprise SAP environments. This release includes