HomeUpdatesSAP: January Security Patch Day fixes critical vulnerabilities

SAP: January Security Patch Day fixes critical vulnerabilities

SAP , a leading enterprise software company , announced the release of 17 security notes as part of its January 2026 Security Patch Day. Of these, four notes address critical vulnerabilities related to SQL injection, remote code execution (RCE), and command injection . Organizations using SAP are urged to apply the updates immediately to avoid serious security breaches.

SAP Security Patch Day

CVE-2026-0501: Critical SQL Injection in S/4HANA

The most severe of the new vulnerabilities, CVE-2026-0501, has a CVSS score of 9.9 and concerns SQL Injection in a module of S/4HANA. Specifically, it affects a Remote Function Call-enabled module based on the ABAP Database Connectivity (ADBC) framework. As security firm Onapsis, the vulnerability allows attackers to execute arbitrary SQL commands via input parameters.

If exploited, an attacker could gain full access to the system, highlighting the severity of the vulnerability for critical business applications that manage financial data, inventory, and personnel information.

See also: Trend Micro patches serious vulnerabilities in Apex Central

CVE-2026-0500: Remote Code Execution in Wily Introscope

The second critical vulnerability, CVE-2026-0500, concerns RCE (Remote Code Execution) in Wily Introscope Enterprise Manager. According to Onapsis, the application allows unauthorized users to create malicious JNLP files, which, if executed by victims via a URL, allow attackers to execute commands on the victim's system.

SAP: January Security Patch Day fixes critical vulnerabilities

The impact of this vulnerability concerns the integrity, confidentiality and availability of data, making rapid remediation critical.

Code import into S/4HANA and Landscape Transformation

CVE -2026-0498 (CVSS 9.1) is a code injection vulnerability in S/4HANA that allows administrators to modify arbitrary source code and execute operating system commands. The issue arises due to incomplete authentication enforcement on remote operating systems.

Similarly, CVE-2026-0491 (CVSS 9.1) concerns Landscape Transformation, where the same vulnerable function appears as a separate DMIS plugin, compromising data management in enterprise environments.

See also: Critical vulnerability in ServiceNow allows privilege escalation

SAP: High severity vulnerabilities and other security notes

In addition to the four critical bugs, SAP announced four high-severity security notes , affecting HANA , ABAP App Server , NetWeaver RFCSDK , Fiori application, and NetWeaver Application Server ABAP/ABAP Platform .

Exploiting these vulnerabilities could allow:

  • Upgrading privileges to administrator privileges
  • Execution of arbitrary commands through specially designed content
  • Privilege escalation due to insufficient authorization
  • Misuse of remote operating units

The remaining nine notes resolve moderate and low severity issues in ERP Central Component, S/4HANA, NetWeaver, Business Connector, Supplier Relationship Management, Fiori, Business Server Pages, Identity Management , and NW AS Java UME User Mapping.

SAP: January Security Patch Day fixes critical vulnerabilities

What should organizations do?

Businesses using SAP should review security advisories and apply updates immediately. SAP applications remain particularly attractive targets for cybercriminals due to their central importance in business operations, financial management, HR and logistics.

See also: CISA: Gogs vulnerability in KEV Catalog

notification and monitoring of security advisories can drastically reduce the risk of a breach, protecting critical information and business processes.

SAP’s January 2026 Security Patch Day shows that traditional ERP platforms remain vulnerable to advanced SQL injection, RCE, and code injection attacks. Continued collaboration with companies like Onapsis and rapid patch implementation are critical to protecting a large number of businesses worldwide.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS