On April 14, 2026, SAP released a critical security patch addressing 19 vulnerabilities, including CVE-2026-27681, a severe SQL injection flaw with a CVSS score of 9.9. This vulnerability affects SAP Business Planning…
On May 12, 2026, SAP released security updates for 15 vulnerabilities, including two critical flaws in Commerce Cloud and S/4HANA. The first critical vulnerability (CVE-2026-34263) allows unauthenticated attackers to…
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
SAP has released critical security patches addressing a code injection vulnerability in SAP Solution Manager (ST 720), tracked as CVE-2025-42880. This vulnerability is rated Critical and affects users of the affected…
On January 2026 Patchday, SAP released 17 security notes addressing vulnerabilities in its software. Among these, four vulnerabilities are classified as critical risks, including a SQL injection vulnerability in SAP…
On February 10, 2026, Microsoft released a security update addressing 59 vulnerabilities, including six zero-day flaws that were actively exploited prior to the patch. The vulnerabilities affect various Microsoft…
SAP has issued its December security updates, fixing 14 vulnerabilities across various products, including three critical-severity flaws. The most severe, CVE-2025-42880, has a CVSS score of 9.9 and involves a code…
SAP has released its November security updates, which include 18 new security advisories. Among these, a critical vulnerability in the SQL Anywhere Monitor (CVE-2025-42890) has been identified, receiving a maximum CVSS…
Microsoft has released updates to address a critical zero-day vulnerability in Windows Shell, tracked as CVE-2026-21510, which is actively being exploited. This security flaw allows remote attackers to bypass essential…
SAP announced a maximum severity security flaw in SQL Anywhere Monitor (Non-GUI), tracked as CVE-2025-42890, which involves hard-coded credentials that could allow arbitrary code execution. The flaw received a CVSS…