-
Non-Product Related Assistance
Request for existing cases, user IDs, Portal navigation support and more
SAP Security Patch Day - January 2026
This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape.
On 13th of January 2026, SAP security patch day saw the release of 17 new security notes. There are no updates to previously released patch day security notes.
Note# | Title | Priority | CVSS |
|---|---|---|---|
[CVE-2026-0501] SQL Injection Vulnerability in SAP S/4HANA Private Cloud and On-Premise (Financials – General Ledger) Product - SAP S/4HANA Private Cloud and On-Premise (Financials – General Ledger) | Critical | ||
[CVE-2026-0500] Remote code execution in SAP Wily Introscope Enterprise Manager (WorkStation) Product - SAP Wily Introscope Enterprise Manager (WorkStation) | Critical | ||
[CVE-2026-0498] Code Injection vulnerability in SAP S/4HANA (Private Cloud and On-Premise) Product - SAP S/4HANA (Private Cloud and On-Premise) | Critical | ||
[CVE-2026-0491] Code Injection vulnerability in SAP Landscape Transformation Product - SAP Landscape Transformation | Critical | ||
[CVE-2026-0492] Privilege escalation vulnerability in SAP HANA database Product - SAP HANA database | High | ||
[CVE-2026-0507] OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK Product - SAP Application Server for ABAP and SAP NetWeaver RFCSDK | High | ||
[CVE-2026-0511] Multiple vulnerabilities in SAP Fiori App (Intercompany Balance Reconciliation) Additional CVE - CVE-2026-0496, CVE-2026-0495 Product - SAP Fiori App (Intercompany Balance Reconciliation) | High | ||
[CVE-2026-0506] Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform Product - SAP NetWeaver Application Server ABAP and ABAP Platform | High | ||
[CVE-2026-0503] Missing Authorization check in SAP ERP Central Component and SAP S/4HANA (SAP EHS Management) Product - SAP ERP Central Component and SAP S/4HANA (SAP EHS Management) | Medium | ||
[CVE-2026-0499] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal Product - SAP NetWeaver Enterprise Portal | Medium | ||
[CVE-2026-0514] Cross-Site Scripting (XSS) vulnerability in SAP Business Connector Product - SAP Business Connector | Medium | ||
[CVE-2026-0513] Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog) Product - SAP Supplier Relationship Management (SICF Handler in SRM Catalog) | Medium | ||
[CVE-2026-0494] Information Disclosure vulnerability in SAP Fiori App (Intercompany Balance Reconciliation) Product - SAP Fiori App (Intercompany Balance Reconciliation) | Medium | ||
[CVE-2026-0493] Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App (Intercompany Balance Reconciliation) Product - SAP Fiori App (Intercompany Balance Reconciliation) | Medium | ||
[CVE-2026-0497] Missing Authorization check in Business Server Pages Application (Product Designer Web UI) Product - Business Server Pages Application (Product Designer Web UI) | Medium | ||
[CVE-2026-0504] Insufficient Input Handling in JNDI Operations of SAP Identity Management Product - SAP Identity Management | Low | ||
[CVE-2026-0510] Obsolete Encryption Algorithm Used in NW AS Java UME User Mapping Product - NW AS Java UME User Mapping | Low |
1 new security note was released after the scheduled monthly patch day. Additionally, 1 previously released security note was updated.
Update to Security Note released on January 2026 Patch Day: [CVE-2026-0491] Code Injection vulnerability in SAP Landscape Transformation Product - SAP Landscape Transformation | Critical | ||
[CVE-2026-23683] Missing Authorization check in SAP Fiori App (Intercompany Balance Reconciliation) Product - SAP Fiori App (Intercompany Balance Reconciliation) | Medium |
To know more about the security researchers and research companies who have contributed for security patches of this month, visit here.
SAP is committed to delivering trustworthy products and cloud services. Secure configuration is essential to ensuring secure operation and data integrity. We have therefore documented security recommendations that are consolidated in this document to help you configure the best security for your SAP portfolio.
Archived blogs from previous years are available here.
If you have any comments or feedback about this post, you can write to secure@sap.com.