-
Non-Product Related Assistance
Request for existing cases, user IDs, Portal navigation support and more
SAP Security Patch Day - April 2026
This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the support portal and applies patches on priority to protect their SAP landscape.
On 14th of April 2026, SAP security patch day saw the release of 19 new security notes. There is 1 update to previously released security note.
Note# | Title | Priority | CVSS |
|---|---|---|---|
[CVE-2026-27681] SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse Product - SAP Business Planning and Consolidation and SAP Business Warehouse | Critical | ||
[CVE-2026-34256] Missing Authorization check in SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) Product - SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise) | High | ||
[CVE-2025-64775] Denial of Service Vulnerability in SAP BusinessObjects Business Intelligence Platform Product - SAP BusinessObjects Business Intelligence Platform | Medium | ||
[CVE-2026-34264] Information Disclosure vulnerability in SAP Human Capital Management for SAP S/4HANA Product - SAP Human Capital Management for SAP S/4HANA | Medium | ||
[CVE-2026-34261] Missing Authorization check in SAP Business Analytics and SAP Content Management Product - SAP Business Analytics and SAP Content Management | Medium | ||
[CVE-2026-27677] Missing Authorization check in SAP S/4HANA OData Service (Manage Reference Equipment) Product - SAP S/4HANA OData Service (Manage Reference Equipment) | Medium | ||
[CVE-2026-27678] Missing Authorization check in SAP S/4HANA Backend OData Service (Manage Reference Structures) Product - SAP S/4HANA Backend OData Service (Manage Reference Structures) | Medium | ||
[CVE-2026-27679] Missing Authorization check in SAP S/4HANA Frontend OData Service (Manage Reference Structures) Product - SAP S/4HANA Frontend OData Service (Manage Reference Structures) | Medium | ||
[CVE-2026-0512] Cross-Site Scripting (XSS) vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog) Product - SAP Supplier Relationship Management (SICF Handler in SRM Catalog) | Medium | ||
[CVE-2026-27674] Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java) Product - SAP NetWeaver Application Server Java (Web Dynpro Java) | Medium | ||
[CVE-2026-34257] Open Redirect vulnerability in SAP NetWeaver Application Server ABAP Product - SAP NetWeaver Application Server ABAP | Medium | ||
[CVE-2026-34262] Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer Product - SAP HANA Cockpit and HANA Database Explorer | Medium | ||
[CVE-2026-27673] Missing Authorization Check in SAP S/4HANA (Private Cloud and On-Premise) Product - SAP S/4HANA (Private Cloud and On-Premise) | Medium | ||
[CVE-2026-27672] Missing Authorization check in Material Master Application Product - Material Master Application | Medium | ||
[CVE-2026-27676] Missing Authorization check in SAP S/4HANA OData Service (Manage Technical Object Structures) Product - SAP S/4HANA OData Service (Manage Technical Object Structures) | Medium | ||
Update to Security Note released on November 2025 Patch Day: [CVE-2025-42899] Missing Authorization check in SAP S4CORE (Manage Journal Entries) | Medium | ||
[CVE-2026-24318] Insecure Session Management vulnerability in SAP BusinessObjects Business Intelligence Platform Product - SAP BusinessObjects Business Intelligence Platform | Medium | ||
[CVE-2026-27683] Reflected cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform Product - SAP BusinessObjects Business Intelligence Platform | Medium | ||
[CVE-2026-27680] CSS Injection vulnerability in SAP NetWeaver Application Server ABAP Product - SAP NetWeaver Application Server ABAP | Low | ||
[CVE-2026-27675] Code Injection vulnerability in SAP Landscape Transformation Product - SAP Landscape Transformation | Low |
To know more about the security researchers and research companies who have contributed for security patches of this month, visit here.
SAP is committed to delivering trustworthy products and cloud services. Secure configuration is essential to ensuring secure operation and data integrity. We have therefore documented security recommendations that are consolidated in this document to help you configure the best security for your SAP portfolio.
Archived blogs from previous years are available here.
If you have any comments or feedback about this post, you can write to secure@sap.com.