Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SAP Urges Immediate Patch for Critical Security Flaws

SAP Urges Immediate Patch for Critical Security Flaws

Posted on March 10, 2026 By CWS

SAP has released a crucial security update as part of its March 2026 Patch Day, introducing 15 new security notes to address vulnerabilities across its product suite. Among these, two critical vulnerabilities stand out, posing a risk of remote code execution and potential system compromise.

Critical Vulnerabilities Identified

This month’s update highlights two critical security issues. The first, tagged as CVE-2019-17571, affects the SAP Quotation Management Insurance application. With a CVSS score of 9.8, this flaw originates from an outdated Apache Log4j component, allowing unauthenticated remote attackers to execute arbitrary code on affected systems. Notably, this is the first patch specifically targeting FS-QUO 800 despite the CVE’s existence since 2019.

The second critical issue, CVE-2026-27685, impacts SAP NetWeaver Enterprise Portal Administration. Rated 9.1 on the CVSS scale, this vulnerability arises from insecure deserialization, enabling a privileged user to upload malicious content, potentially compromising the entire system.

High and Medium Severity Flaws

In addition to the critical vulnerabilities, SAP’s patch addresses a high-severity denial-of-service vulnerability, CVE-2026-27689, in its Supply Chain Management software. This flaw could disrupt system availability and requires immediate attention.

Several medium-severity vulnerabilities are also patched, including a server-side request forgery in SAP NetWeaver Application Server for ABAP, and missing authorization checks across various SAP products. These vulnerabilities could allow unauthorized actions or data access, posing significant risks if left unpatched.

Lower Severity Issues and Recommendations

Lower severity patches include fixes for insecure storage in SAP Customer Checkout and DLL hijacking in SAP GUI for Windows. While these are less critical, they still warrant attention to ensure comprehensive security.

SAP emphasizes the importance of applying the two critical patches immediately, particularly for organizations utilizing SAP NetWeaver, Supply Chain Management, or Business One. Regular patch management aligned with SAP’s monthly updates is essential for maintaining system security.

For further cybersecurity updates and recommendations, follow us on Google News, LinkedIn, and X. Contact us to share your stories and insights.

Cyber Security News Tags:Business One, critical flaws, Cybersecurity, NetWeaver, Patch, remote code execution, SAP, security update, Supply Chain Management, Vulnerabilities

Post navigation

Previous Post: ShinyHunters Exploit Salesforce in New Data Breach Scheme
Next Post: Reducing Attack Surface: Key Strategies Explained

Related Posts

Phishing Scams Exploit LiveChat to Extract User Data Phishing Scams Exploit LiveChat to Extract User Data Cyber Security News
Hackers Abuse Microsoft 365 Exchange Direct Send to Bypass Content Filters and Harvest Sensitive Data Hackers Abuse Microsoft 365 Exchange Direct Send to Bypass Content Filters and Harvest Sensitive Data Cyber Security News
65% of Leading AI Companies Exposes Verified Secrets Including Keys and Tokens on GitHub 65% of Leading AI Companies Exposes Verified Secrets Including Keys and Tokens on GitHub Cyber Security News
Google Uncovered Significant Expansion in ShinyHunters Threat Activity with New Tactics Google Uncovered Significant Expansion in ShinyHunters Threat Activity with New Tactics Cyber Security News
Hackers Exploiting GeoServer RCE Vulnerability to Deploy CoinMiner Hackers Exploiting GeoServer RCE Vulnerability to Deploy CoinMiner Cyber Security News
Microsoft Warns of OneDrive Bug that Causes Searches to Appear Blank Microsoft Warns of OneDrive Bug that Causes Searches to Appear Blank Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution
  • BugHunter Toolkit Enhances Vulnerability Detection
  • OceanLotus Targets Vietnamese Firms with SPECTRALVIPER
  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution
  • BugHunter Toolkit Enhances Vulnerability Detection
  • OceanLotus Targets Vietnamese Firms with SPECTRALVIPER
  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark