# RedRays \- Your SAP Security Solution: RedRays scans your SAP systems for security vulnerabilities \- ABAP, CPI and BTP, one platform\. > RedRays secures SAP end to end \- SAP\-certified platform, penetration testing, ABAP code scanning and 150\+ zero\-day research\. Free 3\-month trial\. Generated by Yoast SEO v27.6, this is an llms.txt file, meant for consumption by LLMs. ## Pages - [SAP Security Platform for Enterprises \| RedRays](https://redrays.io/redrays-security-platform-for-sap-systems/) - [SAP Vulnerability Assessment and Management \| RedRays](https://redrays.io/sap-vulnerability-assessment/) - [SAP Cloud Penetration Testing \| BTP, S/4HANA \| RedRays](https://redrays.io/sap-btp-and-cloud-penetration-testing/) - [SAP Penetration Testing \- Manual SAP Pentest \| RedRays](https://redrays.io/sap-penetration-testing/) - [SAP Threat Modeling Tool \- Open Source \| RedRays](https://redrays.io/threat-modeling-for-sap/) ## Posts - [SAP Security Patch Day August 2026 \| RedRays](https://redrays.io/blog/sap-security-patch-day-august-2026/): SAP Security Patch Day August 2026: 25 security notes, 3 HotNews up to CVSS 9\.9, 7 High priority\. Full breakdown with CVEs, vectors and note links\. - [SAP Note 3765948: Code Injection via SSRF in SAP MII \(CVE\-2026\-44772\)](https://redrays.io/blog/sap-note-3765948-code-injection-ssrf-cve-2026-44772/): CVE\-2026\-44772, CVSS 9\.9: XSL transform parameters let an authenticated user make SAP MII fetch and execute a remote stylesheet\. The gate ships disabled\. - [SAP Note 3758900: Code Injection in SAP MII \(CVE\-2026\-44758\)](https://redrays.io/blog/sap-note-3758900-illumxsltservlet-code-injection-cve-2026-44758/): CVE\-2026\-44758, CVSS 9\.1: the SAP MII IllumXSLTServlet compiled a caller supplied stylesheet\. SAP removed the endpoint rather than patching it\. - [SAP Note 3759854: Directory Traversal in SAP MII \(CVE\-2026\-44763\)](https://redrays.io/blog/sap-note-3759854-ssce-directory-traversal-cve-2026-44763/): CVE\-2026\-44763, CVSS 7\.6: a save path in the SAP MII SSCE interface was assembled without containment, letting files land outside the intended folder\. - [SAP Note 3758657: Scheduling Authorization Gap, SAP MII \(CVE\-2026\-44765\)](https://redrays.io/blog/sap-note-3758657-scheduling-missing-authorization-cve-2026-44765/): CVE\-2026\-44765, CVSS 7\.3: SAP MII scheduling functions were reachable without an authorization check\. The fix adds guards and new role assignments\. ## Footers - [IT Business Main Footer](https://redrays.io/?liquid-footer=it-business-main-footer) - [Footer\_contact](https://redrays.io/?liquid-footer=footer_contact) ## Categories - [sap note](https://redrays.io/blog/category/sap-note/) - [Sap Patch Day](https://redrays.io/blog/category/sap-patch-day/) - [SAP Security](https://redrays.io/blog/category/sap-security/) - [News](https://redrays.io/blog/category/news/) - [ABAP Code Security](https://redrays.io/blog/category/abap-code-security/) ## Tags - [XSS](https://redrays.io/blog/tag/xss/) - [Authorization Check](https://redrays.io/blog/tag/authorization-check/) - [Authorization](https://redrays.io/blog/tag/authorization/) - [Directory Traversal](https://redrays.io/blog/tag/directory-traversal/) - [Cross\-Site Scripting](https://redrays.io/blog/tag/cross-site-scripting/) ## Optional - [Sitemap index](https://redrays.io/sitemap_index.xml)