SAP , a leading enterprise software company , announced the release of 17 security notes as part of its January 2026 Security Patch Day. Of these, four notes address critical vulnerabilities related to SQL injection, remote code execution (RCE), and command injection . Organizations using SAP are urged to apply the updates immediately to avoid serious security breaches.

CVE-2026-0501: Critical SQL Injection in S/4HANA
The most severe of the new vulnerabilities, CVE-2026-0501, has a CVSS score of 9.9 and concerns SQL Injection in a module of S/4HANA. Specifically, it affects a Remote Function Call-enabled module based on the ABAP Database Connectivity (ADBC) framework. As security firm Onapsis, the vulnerability allows attackers to execute arbitrary SQL commands via input parameters.
If exploited, an attacker could gain full access to the system, highlighting the severity of the vulnerability for critical business applications that manage financial data, inventory, and personnel information.
See also: Trend Micro patches serious vulnerabilities in Apex Central
CVE-2026-0500: Remote Code Execution in Wily Introscope
The second critical vulnerability, CVE-2026-0500, concerns RCE (Remote Code Execution) in Wily Introscope Enterprise Manager. According to Onapsis, the application allows unauthorized users to create malicious JNLP files, which, if executed by victims via a URL, allow attackers to execute commands on the victim's system.

The impact of this vulnerability concerns the integrity, confidentiality and availability of data, making rapid remediation critical.
Code import into S/4HANA and Landscape Transformation
CVE -2026-0498 (CVSS 9.1) is a code injection vulnerability in S/4HANA that allows administrators to modify arbitrary source code and execute operating system commands. The issue arises due to incomplete authentication enforcement on remote operating systems.
Similarly, CVE-2026-0491 (CVSS 9.1) concerns Landscape Transformation, where the same vulnerable function appears as a separate DMIS plugin, compromising data management in enterprise environments.
See also: Critical vulnerability in ServiceNow allows privilege escalation
SAP: High severity vulnerabilities and other security notes
In addition to the four critical bugs, SAP announced four high-severity security notes , affecting HANA , ABAP App Server , NetWeaver RFCSDK , Fiori application, and NetWeaver Application Server ABAP/ABAP Platform .
Exploiting these vulnerabilities could allow:
- Upgrading privileges to administrator privileges
- Execution of arbitrary commands through specially designed content
- Privilege escalation due to insufficient authorization
- Misuse of remote operating units
The remaining nine notes resolve moderate and low severity issues in ERP Central Component, S/4HANA, NetWeaver, Business Connector, Supplier Relationship Management, Fiori, Business Server Pages, Identity Management , and NW AS Java UME User Mapping.

What should organizations do?
Businesses using SAP should review security advisories and apply updates immediately. SAP applications remain particularly attractive targets for cybercriminals due to their central importance in business operations, financial management, HR and logistics.
See also: CISA: Gogs vulnerability in KEV Catalog
notification and monitoring of security advisories can drastically reduce the risk of a breach, protecting critical information and business processes.
SAP’s January 2026 Security Patch Day shows that traditional ERP platforms remain vulnerable to advanced SQL injection, RCE, and code injection attacks. Continued collaboration with companies like Onapsis and rapid patch implementation are critical to protecting a large number of businesses worldwide.
