SAP — Cyber Attacks, Breaches & Threat Activity

Threat entity extracted from intelligence sources

Frequency
48
occurrences
First Seen
November 3, 2025
Last Seen
July 17, 2026

SAP is a organization tracked across 36 threat clusters and 48 intelligence report mentions on ThreatCluster. First observed November 3, 2025; most recent activity July 17, 2026.

Related Threat Clusters

  • SAP Releases January 2026 Security Patches for Critical Vulnerabilities

    On January 13, 2026, SAP issued 17 new security notes during its monthly Security Patch Day, addressing critical injection flaws and remote code execution vulnerabilities in key products. Organizations are urged to…

    6 articles · Updated January 13, 2026
  • Operation Escaneo Targets Latin American Critical Infrastructure

    Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…

    4 articles · Updated June 18, 2026
  • SAP Addresses Critical Vulnerabilities in July 2026 Security Updates

    SAP has released security updates addressing 16 vulnerabilities, including three critical flaws in its NetWeaver, Commerce Cloud, and AppRouter products. The most severe, CVE-2026-44747, allows authenticated attackers…

    11 articles · Updated July 14, 2026
  • Critical SQL Injection Vulnerability Discovered in SAP Products

    On April 14, 2026, SAP released a critical security patch addressing 19 vulnerabilities, including CVE-2026-27681, a severe SQL injection flaw with a CVSS score of 9.9. This vulnerability affects SAP Business Planning…

    9 articles · Updated April 14, 2026
  • Checkmarx Jenkins Plugin Compromised by TeamPCP Malware Attack

    Checkmarx reported a malicious version of its Jenkins AST plugin was uploaded to the Jenkins Marketplace on May 9, 2026. This backdoored plugin, which affects security scans in Jenkins CI pipelines, poses a significant…

    15 articles · Updated May 11, 2026
  • SAP Patch Day Addresses Critical Vulnerabilities

    On March 10, 2026, SAP released 15 security notes, including two critical vulnerabilities that could allow remote code execution and system compromise. Administrators are urged to apply the patches promptly to protect…

    10 articles · Updated March 10, 2026
  • Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages

    A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…

    697 articles · Updated April 29, 2026
  • SAP Addresses Critical Vulnerabilities in Commerce Cloud and S/4HANA

    On May 12, 2026, SAP released security updates for 15 vulnerabilities, including two critical flaws in Commerce Cloud and S/4HANA. The first critical vulnerability (CVE-2026-34263) allows unauthenticated attackers to…

    6 articles · Updated May 12, 2026
  • SAP Addresses Critical SQL Anywhere Monitor Vulnerability

    SAP fixed 19 security vulnerabilities, including a critical flaw in SQL Anywhere Monitor that involved hardcoded credentials, potentially allowing remote code execution. The vulnerability, tracked as CVE-2025-42890,…

    2 articles · Updated November 11, 2025
  • PCPJack Malware Targets TeamPCP Victims for Credential Theft

    The newly discovered PCPJack malware framework is actively targeting cloud environments to steal credentials while removing remnants of the TeamPCP cybercrime group. This worm exploits exposed services such as Docker,…

    11 articles · Updated May 7, 2026

Recent Intelligence Reports

  • Abbott Laboratories probes two cyber incidents amid extortion claims — Bleepingcomputer · July 17, 2026
  • SAP warns of critical flaws in NetWeaver and Commerce Cloud — Bleepingcomputer · July 14, 2026
  • Hackers have stopped breaking in. They're abusing the things developers already trust. — Thenextweb · June 19, 2026
  • Operation Escaneo Signals Shift in LatAm Threat Landscape — Darkreading · June 18, 2026
  • How software development’s speed obsession enabled TeamPCP’s chaos crusade — Cyberscoop · June 18, 2026
  • LATAM Infrastructure Hit by Fortinet and Ivanti Exploits — Infosecurity-Magazine · June 18, 2026
  • Operation Escaneo: Infrastructure Exposure, TTP Analysis, and Attribution Assessment of an ... — Cloudsek · June 17, 2026
  • Pathlock Partners with NTT DATA Business Solutions to Deliver Managed SAP ... — Prnewswire · June 16, 2026

CVSS v3.1 Breakdown