Skip to content

SAP Patch Day July 2026: Multiple Critical Vulnerabilities Fixed

In a nutshell: SAP released patches in July 2026 against vulnerabilities that enable arbitrary code execution, SQL injection, cross-site scripting, file manipulation, information disclosure, and circumvention of security controls.

The BSI warns of multiple security flaws in SAP software that can have critical impact — ranging from code execution to SQL injection through to denial-of-service attacks. Patches are available.

The German Federal Office for Information Security (BSI) reports multiple vulnerabilities in SAP software that were fixed with patches in July 2026. The flaws allow an attacker to execute arbitrary program code, perform SQL injection attacks, launch cross-site scripting attacks, manipulate files, and disclose information.

For CISOs, this means an immediate obligation to update in the environment of productive SAP systems. The vulnerabilities encompass both methods to circumvent existing security controls as well as vectors for complete system compromise through arbitrary code execution. Particularly critical are the possibilities for information disclosure in SAP environments, since these systems often process business data and transaction information.

Affected SAP instances should be identified, tested, and updated with the available patches without delay. The BSI provides information under WID-SEC-2026-2308. Prioritisation according to criticality and exposure is necessary to minimise the window for exploitation.


Source: wid.cert-bund.de · Published 29 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: