Vendor
SAP vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 94 vulnerabilities in SAP: 1 in the last 7 days and 43 in the last 90 days, 28 of them critical and 14 exploited in the wild. The most recent, CVE-2026-76974, was published on 22 September 2026. 9 technologies have a page of their own.
- Last 7 days
- 1
- Last 90 days
- 43
- Critical, all time
- 28
- Exploited in the wild
- 14
About SAP
SAP is a multinational software corporation that develops enterprise software to manage business operations and customer relations.
SAP technologies
Latest SAP vulnerabilities
- CVE-2026-76974: SAP Fiori Launchpad input validation bypassmediumCVSS 5.3EPSS 0.4%
- CVE-2026-76971: SAP Manufacturing Integration and Intelligence SSRFmediumCVSS 6.5EPSS 0.3%
- CVE-2026-76969: @sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications…criticalCVSS 9.4EPSS 0.4%
- CVE-2026-76968: SAP Web Dispatcher information disclosuremediumCVSS 6.5EPSS 0.4%
- CVE-2026-76967: SAP NetWeaver Business Client insufficient validation on startup datahighCVSS 7.8EPSS 0.4%
- CVE-2026-76963: SAP NetWeaver authorization bypass in Application Server ABAPmediumCVSS 4.3EPSS 0.3%
- CVE-2026-76962: SAP S/4HANA authorization bypass in Manage Bank Chains appmediumCVSS 4.3EPSS 0.3%
- CVE-2026-76961: SAP S/4HANA Finance CSRF protection bypass in Advanced Payment ManagementlowCVSS 3.5EPSS 0.1%
- CVE-2026-76960: SAP S/4HANA Finance Cross-Site Request Forgery in Advanced Payment ManagementlowCVSS 3.5EPSS 0.1%
- CVE-2026-76959: SAP S/4HANA Finance Advanced Payment Management CSRF protection bypassmediumCVSS 4.6EPSS 0.1%
- CVE-2026-76958: SAP Integration Suite XXE vulnerability in XML validationhighCVSS 8.5EPSS 0.4%
- CVE-2026-66768: SAP GUI for Java trust level policy bypasscriticalCVSS 9EPSS 0.6%
- CVE-2026-66767: SAP NetWeaver Application Server session hijacking via buffered request reprocessinghighCVSS 7.7EPSS 0.4%
- CVE-2026-58240: SAP NetWeaver Message Server authentication bypass in component registrationcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-58234: SAP Process Integration SOAP Adapter denial of servicelowCVSS 2.2EPSS 0.3%
- CVE-2026-44766: SAP S/4HANA SQL injection in Intercompany Matching and ReconciliationmediumCVSS 6.5EPSS 0.4%
- CVE-2026-44756: SAP Extended Passport Protocol memory safety vulnerabilitycriticalCVSS 10EPSS 0.7%
- CVE-2026-66766: SAP S/4HANA ReDoS in third-party componenthighCVSS 7.5EPSS 0.5%
- CVE-2026-58231: SAP Commerce Cloud unauthenticated code execution via default authenticationcriticalCVSS 10EPSS 0.9%
- CVE-2026-66779: SAP NetWeaver Application Server ABAP reflected XSSmediumCVSS 6.3EPSS 0.4%
- CVE-2026-66773: SAP python-pyodata open redirect in OData URL validationmediumCVSS 5.9EPSS 0.3%
- CVE-2026-66772: SAP BusinessObjects Business Intelligence Platform authorization bypass in Admin ToolsmediumCVSS 4.3EPSS 0.3%
- CVE-2026-66771: SAP SAPUI5 stored cross-site scripting in content adaptationmediumCVSS 6.1EPSS 0.4%
- CVE-2026-66770: SAP Social Intelligence SQL injectionmediumCVSS 6.3EPSS 0.3%
- CVE-2026-66764: SAP S/4HANA authorization bypass in Bank Statement reprocessingmediumCVSS 4.3EPSS 0.3%
Most severe SAP vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-31324: SAP NetWeaver Unrestricted File Upload Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2022-22536: SAP Multiple Products HTTP Request Smuggling Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2020-6207: SAP Solution Manager Missing Authentication for Critical Function Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2010-5326: SAP NetWeaver Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2020-6287: SAP NetWeaver Missing Authentication for Critical Function Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2021-38163: SAP NetWeaver Unrestricted File Upload Vulnerabilitycriticalexploited in the wildCVSS 9.9
- CVE-2019-0344: SAP Commerce Cloud Deserialization of Untrusted Data Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2016-2386: SAP NetWeaver SQL Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2025-42999: SAP NetWeaver Deserialization Vulnerabilitycriticalexploited in the wildCVSS 9.1
- CVE-2017-12637: SAP NetWeaver Directory Traversal Vulnerabilitycriticalexploited in the wildCVSS 7.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 5 | 2 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 20 | 3 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 16 | 4 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 1 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/sap.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "SAP vulnerabilities", https://junglewise.ai/threats/vendors/sap, 26 September 2026.