SAP has released its new security update cycle for May 2026 , addressing a total of 15 vulnerabilities affecting its core enterprise products. Among the issues fixed are two critical security vulnerabilities affecting the SAP Commerce Cloud and SAP S / 4HANA platforms , systems used by some of the largest businesses and organizations worldwide.

These platforms are a critical pillar for the operation of large companies. SAP Commerce Cloud is used by international retailers and online stores to manage online sales and digital services, while SAP S/4HANA is the company's new generation cloud ERP, which is gradually replacing the traditional SAP ECC.
Critical vulnerability in SAP Commerce Cloud allows RCE
The most serious of the vulnerabilities fixed is in SAP Commerce Cloud and is tracked as CVE-2026-34263. According to SAP, the issue is related to an incomplete authentication mechanism, which could allow unauthorized attackers to execute malicious code on vulnerable servers.
See also: Apple fixes serious security vulnerabilities
The vulnerability is due to a misconfiguration of the Spring Security framework, which could allow attackers to upload malicious configuration files and launch code injection attacks. If the exploit is successful, an attacker could gain complete control of the server, affecting the confidentiality, integrity, and availability of data.
Security experts point out that such vulnerabilities are considered particularly dangerous for e-commerce environments, as they can lead to the theft of customer information, financial data, or even the interruption of critical business services.
SQL Injection in SAP S/4HANA and the risk of accessing sensitive data
The second critical vulnerability, codenamed CVE-2026-34260, concerns SAP S/4HANA and allows low-sophistication SQL injection attacks. According to SAP's official analysis, the application embeds malicious user input directly into SQL queries without proper validation or sanitization of the data.

Exploiting the vulnerability could allow users with basic privileges to gain unauthorized access to sensitive database information or even cause the application to crash. While SAP says that data integrity is not directly affected, the potential for critical information to be exposed is considered extremely serious.
See also: cPanel – WHM: Fix 3 new vulnerabilities
SAP S/4HANA is one of the most widely used enterprise platforms in the world for managing finances, procurement, logistics and production, which significantly increases the impact of such vulnerabilities.
Multiple fixes for XSS, CSRF and command injection
In addition to the two critical flaws, SAP also patched one high-severity issue and eleven medium-severity vulnerabilities. The fixes cover a wide range of attacks, including command injection, cross-site scripting (XSS), cross-site request forgery (CSRF), authorization bypass, and denial-of-service (DoS).
Although the company states that there is no evidence of active exploitation of the new vulnerabilities, cybersecurity experts warn that SAP systems are a constant target for organized ransomware groups and state-sponsored attackers.
It is no coincidence that the American CISA agency has included 14 different SAP vulnerabilities in the Known Exploited Vulnerabilities list in recent years , confirming that the company's enterprise platforms are often at the center of real cyberattacks.
SAP at the center of attacks on the software supply chain
The new security advisory comes a few weeks after the disclosure of a breach in official SAP npm packages, in a supply chain that aimed to steal credentials and authentication tokens from developers.
This incident once again highlighted the growing threats facing large software companies, particularly in application development and distribution environments. Supply chain attacks are now considered one of the most dangerous forms of cyberattacks, as they allow attackers to gain access to multiple organizations through a single compromised software provider.
See also: cPanel vulnerability used to distribute Filemanager Backdoor

Why organizations need to act immediately
Given that SAP serves 99 of the 100 largest companies worldwide and recorded revenues of over 36 billion euros in 2025, the impact of a potential vulnerability exploit in its products could be enormous.
Security experts recommend immediately installing patches, auditing exposed SAP instances , and continuously monitoring for suspicious activity in enterprise environments. At the same time, it is recommended to implement stricter access policies, enable multifactor authentication, and isolate critical ERP infrastructure from public networks.
This latest security update confirms that enterprise systems remain a key target for modern cyber threats and that timely vulnerability management is now a critical factor in ensuring business continuity.
Source: www.bleepingcomputer.com
