< ciso
brief />
Tag Banner

All news with #sap tag

45 articles

Critical SAP Commerce Cloud RCE Vulnerability Alert

🔔 SAP Commerce Cloud is affected by a maximum-severity vulnerability, CVE-2026-58231, rated 10.0 for insufficient authorization and input validation. An unauthenticated attacker can abuse a default authentication client to send crafted input and trigger arbitrary code execution, risking confidentiality, integrity, and availability. Vendors urge immediate patching and recommend IP filter sets as a temporary mitigation.
read more →

Critical SAP Commerce Cloud RCE Now Being Exploited

🛡️ A maximum-severity remote code execution vulnerability in SAP Commerce Cloud (CVE-2026-58231) patched three days ago is already being targeted in attacks, Defused reports. The flaw, in the core Data Hub Adapter extension, allows unauthenticated actors to exploit improper authorization to execute arbitrary code. SAP warned the issue arises from abuse of a default authentication client and insufficient input validation. Threat researchers observed initial exploitation attempts hitting honeypots despite no public PoC existing.
read more →

SAP Commerce Cloud flaw lets attackers run code

🔒 SAP released patches for a maximum-severity vulnerability in SAP Commerce Cloud (Data Hub Adapter) tracked as CVE-2026-58231, rated 10.0, that could allow arbitrary code execution due to insufficient authorization checks and input validation. Onapsis urged customers to update to the fixed release and re-deploy; as a temporary mitigation, apply an IP Filter Set to restrict access to the vulnerable endpoint. SAP's August 2026 update also addressed three other critical flaws across Manufacturing Integration and Intelligence and ABAP platforms.
read more →

August 2026 Patch Tuesday: Zero‑Day Winsock and SAP CVE

🛡️ Microsoft’s August Patch Tuesday delivers 398 CVE fixes, highlighted by an actively exploited zero‑day in the Windows Ancillary Function Driver for WinSock (CVE‑2026‑68820). The release includes 42 critical and numerous remote code execution flaws that may be exploitable without authentication, plus two additional publicly disclosed zero‑days. SAP released 29 patches, led by a maximum‑severity improper authorization issue in Commerce Cloud’s Data Hub Adapter (CVE‑2026‑58231).
read more →

NVIDIA Leads New Open Secure AI Alliance Initiative

🛡️ NVIDIA has convened nearly 40 technology firms to form the Open Secure AI Alliance, a coalition aimed at building open source security tools for AI, announced on July 27. Members include Adobe, Cisco, Microsoft, CloudStrike, SpaceX, SAP and the Linux Foundation, while notable frontier model developers such as Google, Anthropic and OpenAI are absent. The alliance will focus on finding, fixing and disclosing vulnerabilities, and aims to create an open defense stack for agents, covering identity, isolation, secure model formats and secure coding workflows.
read more →

SAP and Google Cloud launch BDC Connect for BigQuery

🚀 SAP and Google Cloud announced general availability of SAP Business Data Cloud Connect for BigQuery, enabling zero-copy, bi-directional access between SAP Business Data Cloud and BigQuery. The integration exposes SAP tables, metadata, and business semantics directly in BigQuery and Knowledge Catalog to accelerate analytics and agentic AI while reducing data replication and costs. Early adopters report faster data pipelines and improved operational insights.
read more →

SAP July 2026 fixes critical NetWeaver ABAP flaw

🔒 SAP released its July 2026 security updates to remediate multiple serious vulnerabilities, including a critical NetWeaver Application Server ABAP out-of-bounds write (CVE-2026-44747). Vendors and customers are urged to apply the ABAP Kernel patch because the suggested workaround—disabling specific ICF nodes via SICF—may break SAP GUI for HTML. Other addressed issues include an HTTP request/response smuggling bug in Approuter (CVE-2026-27690) and a default-credential OAuth client issue in Commerce Cloud (CVE-2026-44761). SAP notes no evidence of active exploitation but recommends immediate patching and auditing of production instances for sample OAuth clients.
read more →

SAP patches critical NetWeaver, Commerce Cloud flaws

🔒 SAP released July 2026 security updates addressing 16 vulnerabilities across multiple products, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. The issues include a memory corruption bug in NetWeaver AS ABAP, an HTTP request smuggling flaw in Approuter, and default-credential exposure in Commerce Cloud. SAP also fixed several high- and medium-severity bugs such as RCE, XSS, SQLi, and DLL hijacking.
read more →

Amazon EC2 U7i-8TB high memory instances in Paris

🔥 Amazon EC2 High Memory U7i-8TB instances (u7i-8tb.112xlarge) are now available in the AWS Europe (Paris) region. These 7th-generation U7i instances are powered by custom 4th-generation Intel Xeon Scalable (Sapphire Rapids) processors and provide 8 TiB of DDR5 memory for scaling transaction processing throughput. They deliver 448 vCPUs, up to 100 Gbps EBS and network bandwidth, ENA Express, and up to 45% better price performance versus U-1 instances. U7i instances are targeted at mission-critical in-memory databases such as SAP HANA, Oracle, and SQL Server.
read more →

Critical patches from Fortinet, Ivanti and SAP released

🛡️ Fortinet, Ivanti, and SAP issued security updates addressing multiple critical vulnerabilities that could enable arbitrary code execution and data disclosure. Fortinet fixed a command injection in FortiSandbox (CVE-2026-25089, CVSS 9.1). Ivanti patched two critical Ivanti Sentry flaws (CVE-2026-10520, CVSS 10.0; CVE-2026-10523, CVSS 9.9) that allow remote code execution and admin account creation. SAP released fixes for four critical issues across NetWeaver, ABAP Platform, Commerce Cloud, and Data Hub.
read more →

June Patch Tuesday: Record CVE Count and Critical Fixes

🔒 June Patch Tuesday brought an unprecedented wave of fixes: Microsoft released over 200 CVEs including three disclosed zero-days and 32 critical patches, while SAP and Adobe patched multiple high-severity enterprise flaws. Microsoft warns this increase may become the new normal as AI accelerates vulnerability discovery, urging risk-based prioritization and automated patching. Administrators should urgently assess critical kernel, Active Directory, Hyper-V, and Exchange fixes.
read more →

SAP patches critical NetWeaver and Commerce Cloud flaws

🔒 SAP released its June 2026 security update addressing 15 vulnerabilities, including four critical issues affecting SAP NetWeaver and SAP Commerce Cloud. The critical flaws include XML Signature Wrapping (CVE-2026-44748), a memory corruption bug (CVE-2026-27671), a Spring Security-related issue (CVE-2026-22732), and a directory traversal in the Java web container (CVE-2026-40128). Organizations should prioritize patching these high-impact defects immediately.
read more →

Critical Patches for Ivanti, Fortinet, SAP, VMware, n8n

🔒 Ivanti, Fortinet, SAP, VMware, n8n and dozens of other vendors have released security updates addressing multiple high- and critical-severity flaws that enable authentication bypass, information disclosure, local privilege escalation, and remote code execution. Highlights include a critical Ivanti Xtraction file-name control flaw (CVE-2026-8043), Fortinet authentication and sandbox execution bugs, SAP SQL injection and missing-auth issues, and a TOCTOU local privilege escalation in VMware Fusion. Administrators should prioritize applying the vendor-recommended patches immediately.
read more →

SAP SAPPHIRE 2026: Google Cloud AI Agents and Data

🔔At SAP SAPPHIRE, Google Cloud and SAP introduced a Unified Data Foundation to connect SAP business data directly into BigQuery and enable agentic AI workflows. Announcements include BDC Connect for BigQuery GA with zero-copy access, new 48TB X5 memory-optimized instances, a SecNumCloud-qualified Sovereign Cloud with S3NS, and Google SecOps for SAP in preview. The new Cortex Framework preview aims to accelerate building agentic solutions while maintaining enterprise governance and reducing data movement.
read more →

Microsoft and SAP Advance Enterprise AI on Azure, Sapphire

🚀 At SAP Sapphire 2026, Microsoft and SAP announced expanded integrations to embed AI across SAP applications on Azure, emphasizing Microsoft IQ as a shared intelligence layer and agent-to-agent capabilities between Copilot and Joule. The updates include bi-directional, zero-copy delta sharing with SAP Business Data Cloud and Microsoft Fabric, sovereign cloud expansions, and an enlarged RISE with SAP acceleration program. These developments aim to move enterprises from experimentation to production-ready, governed AI at scale.
read more →

SAP May 2026 Fixes Critical Flaws in Commerce Cloud

🔒 SAP released its May 2026 security updates addressing 15 vulnerabilities across multiple products, including two critical flaws affecting Commerce Cloud and S/4HANA. The most severe (CVE-2026-34263) is a missing authentication check in Commerce Cloud that can allow unauthenticated remote code execution via improper Spring Security configuration. The other critical (CVE-2026-34260) permits low-complexity SQL injection by attackers with basic privileges, risking sensitive data exposure and potential service crashes. SAP also patched one high and 11 medium-severity issues and reports no evidence of in-the-wild exploitation to date.
read more →

AWS Expands EC2 X8i Instances to Dublin and Mumbai

🖥️ Amazon has launched EC2 X8i instances in Europe (Ireland) and Asia Pacific (Mumbai), powered by AWS-exclusive Intel Xeon 6 processors and certified for SAP. These memory-optimized instances deliver up to 1.5x more memory (up to 6 TB), 3.3x greater memory bandwidth, and up to 43% higher performance compared with prior X2i generations. Offered in 14 sizes from large to 96xlarge, including two bare-metal options, X8i targets SAP HANA, large databases, data analytics, and EDA, and is available via Savings Plans, On-Demand, or Spot.
read more →

Supply Chain npm Attack Targets SAP Developer Tools

🔒 A supply-chain campaign dubbed "mini Shai-Hulud" infected SAP-related npm packages in late April, inserting install-time malware that harvested developer credentials, GitHub and npm tokens, GitHub Actions secrets, and cloud credentials across AWS, Azure, GCP and Kubernetes. Researchers identified affected packages including mbt@1.2.48 and several @cap-js modules. The malicious releases were later replaced with safe versions.
read more →

SAP npm Packages Compromised in Credential-Stealing Attack

🔒 Multiple official SAP npm packages were recently compromised in a supply-chain operation that installs a malicious preinstall script during package installation. The script downloads the Bun runtime and executes an obfuscated payload that harvests a wide range of secrets — including npm and GitHub tokens, SSH keys, cloud credentials, Kubernetes configs, and CI/CD environment variables — and exfiltrates them to public GitHub repositories. Researchers attribute the campaign with medium confidence to TeamPCP and warn it includes self-propagation logic to modify other packages using stolen credentials.
read more →

Supply-Chain Attack Targets SAP-Related npm Packages

⚠️ Researchers have uncovered a supply-chain campaign dubbed the "mini Shai-Hulud" that poisoned multiple SAP-related npm packages to install credential-stealing malware during installation. The malicious releases added a preinstall hook that fetched and executed a platform-specific Bun binary, harvesting local credentials, GitHub and npm tokens, CI secrets, and cloud credentials. Analysts from Aikido Security, SafeDep, Socket, StepSecurity and Wiz advise rotating tokens, inspecting workflows, and upgrading to patched releases.
read more →