HomeUpdatesSAP Patch Day March: Multiple vulnerabilities fixed

SAP Patch Day March: Multiple vulnerabilities fixed

SAP has released 15 new security bulletins as part of its March 2026 Patch Day , addressing multiple vulnerabilities in key products in its ecosystem. Among the issues fixed are two critical security flaws that could allow attackers to remotely execute malicious code and gain complete control of corporate systems .

SAP

The company urges organizations using its platforms to immediately visit the SAP Support Portal and apply the available updates. The vulnerabilities affect products that are widely used in enterprise environments, making updates particularly critical to maintaining the security of information infrastructures.

Critical vulnerability in SAP Quotation Management Insurance

The most serious issue addressed this month is the CVE-2019-17571, which has an extremely high CVSS severity score of 9.8. The issue affects the SAP Quotation Management Insurance (FS-QUO 800) application, a system used in the insurance industry to manage quotes and contracts.

See also: CISA: SolarWinds, Ivanti and Workspace One vulnerabilities on KEV list

The vulnerability is related to an outdated Apache Log4j SocketServer component that is built into the product. This class accepts and processes serialized log events without requiring authentication. This means that a remote attacker could send specially crafted data and execute arbitrary code on the server.

Although the CVE identifier was created in 2019, this update marks the first time a patch has been issued specifically for the FS-QUO 800 version. This highlights a common problem in enterprise software: older components can remain active and vulnerable for years within complex systems.

Critical vulnerability in SAP NetWeaver Enterprise Portal Administration

The second critical vulnerability, CVE-2026-27685, has a CVSS score of 9.1 and affects SAP NetWeaver Enterprise Portal Administration running EP-RUNTIME 7.50. The vulnerability is related to unsafe data deserialization.

In practice, a user with privileges on the system could upload malicious content which, when processed by the server, leads to a serious breach of the confidentiality, integrity and availability of the system. In other words, the vulnerability could be used as a gateway to complete control of the server.

The problem is addressed through SAP Security Note 3714585, which administrators are urged to implement immediately.

SAP Patch Day March: Multiple vulnerabilities fixed

High severity vulnerabilities in supply chain systems

In addition to the two critical issues, SAP also patched a high-severity vulnerability in SAP Supply Chain Management. The vulnerability, CVE-2026-27689, with a CVSS score of 7.7, could lead to denial of service attacks.

See also: CISA: New Apple vulnerabilities in the KEV Catalog

The vulnerability affects multiple versions of SCMAPO, S4CORE, S4COREOP, and SCM. An attacker with low privileges but a valid user identity could exploit the issue over a network to disrupt the operation of supply chain systems.

For businesses that rely on SAP for logistics and production management, such an outage could cause serious operational consequences.

Multiple vulnerabilities of medium severity

The update batch also includes several medium-severity vulnerabilities affecting core SAP platforms. Among them is an SSRF vulnerability in SAP NetWeaver Application Server for ABAP (CVE-2026-24316), which could allow attackers to send unauthorized requests to internal system resources.

Another issue, CVE-2026-24309, relates to incomplete authorization checking in the same ABAP environment. This vulnerability could allow unauthorized data changes or even service disruption.

In addition, a SQL Injection vulnerability was identified in SAP NetWeaver Feedback Notification (CVE-2026-27684), which could lead to partial data leakage. In addition, a Cross-Site Scripting affects SAP Business One Job Service on HANA-based versions.

Lower severity but important updates

The fixes also include less critical issues, such as insecure storage issues in SAP Customer Checkout 2.0 and a potential DLL abuse in the SAP GUI for Windows when using the GuiXT tool.

Also addressed were issues related to older versions of OpenSSL in SAP NetWeaver AS Java's Adobe Document Services component, as well as another authorization issue in SAP NetWeaver.

See also: Critical vulnerability in Nginx UI exposes backups

Although these vulnerabilities are classified as lower severity, SAP emphasizes that they should be addressed as part of an overall update management plan.

SAP Patch Day March: Multiple vulnerabilities fixed

The importance of the regular security update cycle

SAP releases security updates on the second Tuesday of each month as part of its established Patch Day process. For businesses that rely on SAP systems, aligning with this update cycle is a critical part of their cybersecurity strategy.

Experts emphasize that organizations must implement structured patch management processes, assess vulnerabilities affecting their own installations, and apply relevant fixes without delay.

In an environment where cyberattacks increasingly target enterprise ERP systems and cloud infrastructures, rapid installation of updates remains one of the most effective protection measures.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS