Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SAP Addresses Critical Bugs in FS-QUO and NetWeaver

SAP Addresses Critical Bugs in FS-QUO and NetWeaver

Posted on March 10, 2026 By CWS

On Tuesday, SAP, a leading enterprise security company, released 15 new security notes as part of its March 2026 Security Patch Day initiative. These updates aim to address critical security vulnerabilities in their systems.

Critical Vulnerabilities in FS-QUO and NetWeaver

The most significant of these updates concern critical flaws identified in Quotation Management Insurance (FS-QUO) and NetWeaver Enterprise Portal Administration. SAP has highlighted a severe code injection vulnerability within FS-QUO, which is recorded as CVE-2019-17571 with a CVSS score of 9.8.

This vulnerability, initially discovered in December 2019, involves the deserialization of untrusted data in Apache Log4j, potentially allowing remote code execution under specific circumstances.

Another critical vulnerability, known as CVE-2026-27685, also involves deserialization of untrusted data. With a CVSS score of 9.1, this issue could enable attackers to introduce malicious data that, when processed, might lead to code execution or even a denial-of-service (DoS).

Additional Security Concerns Addressed

In addition to these critical vulnerabilities, SAP’s March 2026 patch includes a fix for CVE-2026-27689, a high-severity DoS vulnerability in their Supply Chain Management system. This flaw allows for the repeated execution of a function with a large loop control parameter, which can exhaust system resources.

The remaining security notes address medium-severity issues across various SAP products such as NetWeaver, Business One, Business Warehouse, S/4HANA, and others. These issues include server-side request forgery (SSRF), missing authorization checks, SQL injections, cross-site scripting (XSS), insecure storage, DLL hijacking, and DoS vulnerabilities.

Importance of Timely Updates

SAP has not reported any active exploitation of these vulnerabilities in the wild. However, users are strongly advised to update their systems promptly to mitigate potential risks.

Keeping systems updated is crucial to maintain security and prevent attackers from exploiting these vulnerabilities. Regular patching ensures that potential entry points for cyber threats are minimized, safeguarding sensitive enterprise data.

By addressing these vulnerabilities, SAP continues to reinforce its commitment to providing secure and reliable software solutions for its users worldwide.

Security Week News Tags:code injection, Cybersecurity, Deserialization, FS-QUO, NetWeaver, Patch, SAP, Security, software update, Vulnerabilities

Post navigation

Previous Post: KadNap Malware Uses Asus Routers for Stealth Botnet
Next Post: Chinese Cyber Threat Targets Qatar Amid Middle East Unrest

Related Posts

Trend Micro Patches Critical Code Execution Flaw in Apex Central Trend Micro Patches Critical Code Execution Flaw in Apex Central Security Week News
Volvo Group Employee Data Stolen in Ransomware Attack Volvo Group Employee Data Stolen in Ransomware Attack Security Week News
US Halts Russian Espionage Using Hacked Routers and DNS Tricks US Halts Russian Espionage Using Hacked Routers and DNS Tricks Security Week News
Critical WatchGuard Firebox Vulnerability Exploited in Attacks Critical WatchGuard Firebox Vulnerability Exploited in Attacks Security Week News
Alleged Chinese State Hacker Wanted by US Arrested in Italy Alleged Chinese State Hacker Wanted by US Arrested in Italy Security Week News
Russian APT Exploiting 7-Year-Old Cisco Vulnerability: FBI Russian APT Exploiting 7-Year-Old Cisco Vulnerability: FBI Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Early Cyber Weapon ‘fast16’ Revealed by Researchers
  • Microsoft Fixes Vulnerability in Entra Agent ID Administration
  • CISA Highlights New Security Flaws, Sets 2026 Deadline
  • Hackers Target Cisco Devices with Known Vulnerabilities
  • ADT Faces Data Breach After ShinyHunters Claim

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Early Cyber Weapon ‘fast16’ Revealed by Researchers
  • Microsoft Fixes Vulnerability in Entra Agent ID Administration
  • CISA Highlights New Security Flaws, Sets 2026 Deadline
  • Hackers Target Cisco Devices with Known Vulnerabilities
  • ADT Faces Data Breach After ShinyHunters Claim

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark