SAP — Cyber Attacks, Breaches & Threat Activity

Threat entity extracted from intelligence sources

Frequency
57
occurrences
First Seen
November 3, 2025
Last Seen
September 9, 2026

Related Threat Clusters

  • SAP Releases January 2026 Security Patches for Critical Vulnerabilities

    On January 13, 2026, SAP issued 17 new security notes during its monthly Security Patch Day, addressing critical injection flaws and remote code execution vulnerabilities in key products. Organizations are urged to…

    6 articles · Updated January 13, 2026
  • Operation Escaneo Targets Latin American Critical Infrastructure

    Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…

    4 articles · Updated June 18, 2026
  • Critical OVERPASS Vulnerability in SAP Kernel Requires Immediate Action

    On September 8, 2026, SAP released security updates addressing 20 vulnerabilities, including a critical memory corruption flaw tracked as CVE-2026-44756, named OVERPASS. This vulnerability allows unauthenticated…

    15 articles · Updated September 8, 2026
  • SAP Addresses Critical Vulnerabilities in July 2026 Security Updates

    SAP has released security updates addressing 16 vulnerabilities, including three critical flaws in its NetWeaver, Commerce Cloud, and AppRouter products. The most severe, CVE-2026-44747, allows authenticated attackers…

    11 articles · Updated July 14, 2026
  • Critical SQL Injection Vulnerability Discovered in SAP Products

    On April 14, 2026, SAP released a critical security patch addressing 19 vulnerabilities, including CVE-2026-27681, a severe SQL injection flaw with a CVSS score of 9.9. This vulnerability affects SAP Business Planning…

    9 articles · Updated April 14, 2026
  • Checkmarx Jenkins Plugin Compromised by TeamPCP Malware Attack

    Checkmarx reported a malicious version of its Jenkins AST plugin was uploaded to the Jenkins Marketplace on May 9, 2026. This backdoored plugin, which affects security scans in Jenkins CI pipelines, poses a significant…

    15 articles · Updated May 11, 2026
  • SAP Patch Day Addresses Critical Vulnerabilities

    On March 10, 2026, SAP released 15 security notes, including two critical vulnerabilities that could allow remote code execution and system compromise. Administrators are urged to apply the patches promptly to protect…

    10 articles · Updated March 10, 2026
  • University of Pennsylvania SSO Breach Exposes 1.2 Million Records

    In 2025, the University of Pennsylvania suffered a significant data breach due to a compromised single sign-on (SSO) account. Attackers accessed the PennKey SSO, infiltrating internal systems including VPN, Salesforce,…

    2 articles · Updated July 29, 2026
  • Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages

    A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…

    753 articles · Updated April 29, 2026
  • SAP Addresses Critical Vulnerabilities in Commerce Cloud and S/4HANA

    On May 12, 2026, SAP released security updates for 15 vulnerabilities, including two critical flaws in Commerce Cloud and S/4HANA. The first critical vulnerability (CVE-2026-34263) allows unauthenticated attackers to…

    6 articles · Updated May 12, 2026

Recent Intelligence Reports

  • SAP Patches Maximum Severity “Overpass” Flaw — Infosecurity-Magazine · September 9, 2026
  • SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution — Thehackernews · September 9, 2026
  • Sap Overpass Remediation — onapsis.com · September 8, 2026
  • SAP Patches Critical Extended Passport Processing Vulnerability — Securityweek · September 8, 2026
  • Sevii Targets AI — Feeds.Feedburner · September 1, 2026
  • Patch Day: SAP Commerce Cloud fully compromisable — Heise.De · August 11, 2026
  • Critical SAP Vulnerabilities Let Attackers Inject Malicious Code and Corrupt Memory — Cybersecuritynews · August 11, 2026
  • University of Pennsylvania breach highlights SSO security risks — Feeds.Feedburner · July 29, 2026

CVSS v3.1 Breakdown