Skip to content
Critical Vulnerabilities in SAP Commerce Cloud and SAP S/4HANA

Critical Vulnerabilities in SAP Commerce Cloud and SAP S/4HANA

Csa.Sg • May 13, 2026

SAP has released security updates to address critical vulnerabilities in SAP Commerce Cloud and SAP S/4HANA. Users and administrators of affected products are advised to update to the latest versions immediately.

SAP has released security updates to address critical vulnerabilities affecting SAP Commerce Cloud (CVE-2026-34263), and SAP S/4HANA (CVE-2026-34260), as part of SAP's Security Patch Day in May 2026. Both vulnerabilities have a Common Vulnerability Scoring System (CVSSv3.1) score of 9.6 out of 10.

Successful exploitation of these vulnerabilities could lead to the following:

CVE-2026-34263: Due to an improper Spring Security configuration, an unauthenticated attacker could upload malicious configuration files to perform arbitrary code execution on the affected system.

CVE-2026-34260: Due to insufficient input validation in the SAP Enterprise for ABAP component, an authenticated attacker could inject malicious SQL statements to gain unauthorised access to sensitive database information or cause application crashes on the affected system.

These vulnerabilities affect the following SAP products and versions:

SAP Commerce Cloud versions: HY_COM 2205, COM_CLOUD 2211, COM_CLOUD 2211-JDK21

SAP S/4HANA (SAP Enterprise for ABAP) versions: SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816

Users and administrators of affected products are advised to update to the latest versions immediately.

Extracted Entities