Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SAP Security Patch Day – March 2026

SAP has released its March 2026 security patch package containing 15 security notes addressing vulnerabilities across enterprise SAP environments. This release includes two HotNews vulnerabilities with CVSS ratings up to 9.8, one High priority issue, eleven Medium priority fixes, and one Low priority update. The patches affect SAP NetWeaver, SAP Business One, SAP Supply Chain Management, SAP Business Warehouse, and other application components. Six of these vulnerabilities were identified by the RedRays research team using our ABAP Code Scanner.

Total Security Notes
15
HotNews Critical
2
High Priority
1
Medium Priority
11
Low Priority
1
Found by RedRays
6

Executive Summary

  • Critical Code Injection: CVE-2019-17571 (CVSS 9.8) in SAP Quotation Management Insurance application (FS-QUO) leverages a known Apache Log4j 1.2 deserialization flaw, allowing unauthenticated remote code execution with complete system compromise.
  • Critical Insecure Deserialization: CVE-2026-27685 (CVSS 9.1) in SAP NetWeaver Enterprise Portal Administration enables high-privileged attackers to exploit deserialization to achieve arbitrary code execution with cross-scope impact.
  • Supply Chain DoS: CVE-2026-27689 (CVSS 7.7) in SAP Supply Chain Management allows authenticated attackers to cause denial of service with high availability impact.
  • SQL Injection: CVE-2026-27684 (CVSS 6.4) in SAP NetWeaver Feedback Notification, discovered by RedRays, enables SQL injection attacks with cross-scope impact on confidentiality and availability.

Vulnerabilities Discovered by RedRays

RedRays ABAP Code Scanner

Six vulnerabilities in this Patch Day were discovered by RedRays ABAP Code Scanner and responsibly disclosed to SAP through our coordinated vulnerability disclosure process.

These findings were identified using the RedRays ABAP Code Scanner - our automated static analysis tool designed to detect security issues in custom ABAP code before they reach production.

  • 6.4 CVE-2026-27684 SQL Injection in SAP NetWeaver (Feedback Notification)
  • 6.4 CVE-2026-24316 SSRF in SAP NetWeaver Application Server for ABAP
  • 6.4 CVE-2026-24309 Missing Authorization check in SAP NetWeaver Application Server for ABAP
  • 5.9 CVE-2026-27686 Missing Authorization check in SAP Business Warehouse (Service API)
  • 5.0 CVE-2026-27688 Missing Authorization check in SAP NetWeaver Application Server for ABAP
  • 3.5 CVE-2026-24310 Missing Authorization check in SAP NetWeaver Application Server for ABAP

Critical HotNews Vulnerabilities

Code Injection vulnerability in SAP Quotation Management Insurance application (FS-QUO)

9.8 CVE-2019-17571 FS-QUO Code Injection
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Critical code injection vulnerability in SAP Quotation Management Insurance application leveraging a known Apache Log4j 1.2 deserialization flaw. Unauthenticated remote attackers can execute arbitrary code without any user interaction, leading to complete compromise of confidentiality, integrity, and availability.

SAP Note 3698553 — emergency patch required immediately.

Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration

9.1 CVE-2026-27685 BC-PIN-PCD Insecure Deserialization
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Critical insecure deserialization vulnerability in SAP NetWeaver Enterprise Portal Administration allows high-privileged attackers to inject malicious serialized objects. Successful exploitation leads to cross-scope impact with complete compromise of confidentiality, integrity, and availability across the portal environment.

SAP Note 3714585 — patch within 24 hours.

High Priority Security Issues

Denial of service (DOS) in SAP Supply Chain Management

7.7 CVE-2026-27689 SCM-APO-INT-EXT DoS
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Denial of service vulnerability in SAP Supply Chain Management allows authenticated attackers to disrupt service availability with cross-scope impact. High severity threat to business continuity and supply chain operations.

SAP Note 3719502 — apply high priority patch.

Medium Priority Vulnerabilities

SQL Injection Vulnerability in SAP NetWeaver (Feedback Notification)

6.4 CVE-2026-27684 CA-NO SQL Injection RedRays
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L

SQL injection vulnerability in SAP NetWeaver (Feedback Notification) allows authenticated attackers to inject malicious SQL statements, leading to cross-scope impact on confidentiality and availability of business-critical data.

SAP Note 3697355 — schedule patch.

Server-Side Request Forgery (SSRF) in SAP NetWeaver Application Server for ABAP

6.4 CVE-2026-24316 BC-TWB-TST-ECA SSRF RedRays
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Server-Side Request Forgery vulnerability in SAP NetWeaver Application Server for ABAP allows authenticated attackers to forge requests from the server to access internal services and resources with cross-scope impact on confidentiality and integrity.

SAP Note 3689080 — schedule patch.

Missing Authorization check in SAP NetWeaver Application Server for ABAP

6.4 CVE-2026-24309 BC-DB-ORA-CCM Missing Auth RedRays
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L

Missing authorization check in SAP NetWeaver Application Server for ABAP allows authenticated attackers to bypass authorization controls with cross-scope impact on system integrity and availability.

SAP Note 3703856 — apply update.

DOM-based Cross-Site Scripting (XSS) Vulnerability in SAP Business One (Job Service)

6.1 CVE-2026-0489 SBO-CRO-SEC XSS
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

DOM-based Cross-Site Scripting vulnerability in SAP Business One (Job Service) allows unauthenticated attackers to inject malicious scripts through DOM manipulation, leading to cross-scope impact on confidentiality and integrity when users interact with crafted content.

SAP Note 3693543 — schedule patch.

Missing Authorization check in SAP Business Warehouse (Service API)

5.9 CVE-2026-27686 BC-BW Missing Auth RedRays
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H

Missing authorization check in SAP Business Warehouse (Service API) allows authenticated attackers to bypass access controls under complex conditions, with impact on integrity and high impact on availability of BW services.

SAP Note 3703385 — schedule update.

Missing Authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal

5.8 CVE-2026-27687 PY-PT Missing Auth
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

Missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal allows high-privileged attackers to access sensitive HR data under complex conditions with cross-scope impact on confidentiality.

SAP Note 3701020 — apply patch.

Insecure Storage Protection vulnerability in SAP Customer Checkout 2.0

5.6 CVE-2026-24311 IS-SE-CCO Insecure Storage
CVSS:3.0/AV:P/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L

Insecure storage protection vulnerability in SAP Customer Checkout 2.0 allows attackers with physical access and high privileges to access protected data, with high impact on confidentiality and integrity of checkout systems.

SAP Note 3708457 — schedule update.

Missing Authorization check in SAP Solution Tools Plug-In (ST-PI)

5.0 CVE-2026-24313 SV-SMG-SDD Missing Auth
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Missing authorization check in SAP Solution Tools Plug-In (ST-PI) allows authenticated attackers to access sensitive system information with cross-scope impact on confidentiality.

SAP Note 3707930 — apply fix.

Missing Authorization check in SAP NetWeaver Application Server for ABAP

5.0 CVE-2026-27688 BC-DB-SDB Missing Auth RedRays
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Missing authorization check in SAP NetWeaver Application Server for ABAP allows authenticated attackers to access sensitive system information with cross-scope impact on confidentiality.

SAP Note 3704740 — apply fix.

DLL Hijacking vulnerability in SAP GUI for Windows with active GuiXT

5.0 CVE-2026-24317 BC-FES-GXT DLL Hijacking
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

DLL Hijacking vulnerability in SAP GUI for Windows with active GuiXT allows attackers to load malicious DLL files when users launch the application, leading to low impact on confidentiality, integrity, and availability.

SAP Note 3699761 — maintenance window.

Denial of Service due to Outdated OpenSSL Version in SAP NetWeaver AS Java (Adobe Document Services)

4.3 Multiple CVEs BC-SRV-FP DoS
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Multiple denial of service vulnerabilities due to an outdated OpenSSL version in SAP NetWeaver AS Java (Adobe Document Services) allow authenticated attackers to disrupt document processing with low impact on availability.

SAP Note 3700960 — routine update.

Low Priority Security Updates

Missing Authorization check in SAP NetWeaver Application Server for ABAP

3.5 CVE-2026-24310 BC-DB-INF Missing Auth RedRays
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N

Missing authorization check in SAP NetWeaver Application Server for ABAP allows authenticated attackers to access limited system information under complex conditions with cross-scope confidentiality impact.

SAP Note 3694383 — regular maintenance cycle.

Explore More

SAP Security Patch Day February 2026

SAP has released its February 2026 security patch package containing 27 security notes addressing critical vulnerabilities across enterprise SAP environments. This release