-
Non-Product Related Assistance
Request for existing cases, user IDs, Portal navigation support and more
SAP Security Patch Day - March 2026
This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape.
On 10th of March 2026, SAP security patch day saw the release of 15 new security notes. There are no updates to previously released patch day security notes.
Note# | Title | Priority | CVSS |
|---|---|---|---|
[CVE-2019-17571] Code Injection vulnerability in SAP Quotation Management Insurance application (FS-QUO) Product - SAP Quotation Management Insurance application (FS-QUO) | Critical | ||
[CVE-2026-27685] Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration Product - SAP NetWeaver Enterprise Portal Administration | Critical | ||
[CVE-2026-27689] Denial of service (DOS) in SAP Supply Chain Management Product - SAP Supply Chain Management | High | ||
[CVE-2026-24316] Server-Side Request Forgery (SSRF) in SAP NetWeaver Application Server for ABAP Product - SAP NetWeaver Application Server for ABAP | Medium | ||
[CVE-2026-24309] Missing Authorization check in SAP NetWeaver Application Server for ABAP Product - SAP NetWeaver Application Server for ABAP | Medium | ||
[CVE-2026-27684] SQL Injection Vulnerability in SAP NetWeaver (Feedback Notification) Product - SAP NetWeaver (Feedback Notification) | Medium | ||
[CVE-2026-0489] DOM-based Cross-Site Scripting (XSS) Vulnerability in SAP Business One (Job Service) Product - SAP Business One (Job Service) | Medium | ||
[CVE-2026-27686] Missing Authorization check in SAP Business Warehouse (Service API) Product - SAP Business Warehouse (Service API) | Medium | ||
[CVE-2026-27687] Missing Authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal Product - SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal | Medium | ||
[CVE-2026-24311] Insecure Storage Protection vulnerability in SAP Customer Checkout 2.0 Product - SAP Customer Checkout 2.0 | Medium | ||
[CVE-2026-24317] DLL Hijacking vulnerability in SAP GUI for Windows with active GuiXT Product - SAP GUI for Windows with active GuiXT | Medium | ||
[CVE-2026-27688] Missing Authorization check in SAP NetWeaver Application Server for ABAP Product - SAP NetWeaver Application Server for ABAP | Medium | ||
[CVE-2026-24313] Missing Authorization check in SAP Solution Tools Plug-In (ST-PI) Product - SAP Solution Tools Plug-In (ST-PI) | Medium | ||
[Multiple CVEs] Denial of Service due to Outdated OpenSSL Version in SAP NetWeaver AS Java (Adobe Document Services) Related CVEs - CVE-2025-9230, CVE-2025-9232 | Medium | ||
[CVE-2026-24310] Missing Authorization check in SAP NetWeaver Application Server for ABAP Product - SAP NetWeaver Application Server for ABAP | Low |
2 previously released security notes were updated after the scheduled monthly patch day.
Update to Security Note released on February 2026 Patch Day: [CVE-2026-0485] Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platform Product - SAP BusinessObjects BI Platform | High | ||
Update to Security Note released on March 2026 Patch Day: [CVE-2026-24316] Server-Side Request Forgery (SSRF) in SAP NetWeaver Application Server for ABAP Product - SAP NetWeaver Application Server for ABAP
| Medium |
To know more about the security researchers and research companies who have contributed for security patches of this month, visit here.
SAP is committed to delivering trustworthy products and cloud services. Secure configuration is essential to ensuring secure operation and data integrity. We have therefore documented security recommendations that are consolidated in this document to help you configure the best security for your SAP portfolio.
Archived blogs from previous years are available here.
If you have any comments or feedback about this post, you can write to secure@sap.com.