Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · sap

sap

· 90 Critical

Total CVEs

1,571

Critical

90

Products

429

Search All CVEs →

1,571

Products (429)

3d visual enterprise viewer131 CVEsnetweaver104 CVEsnetweaver application server abap78 CVEsbusinessobjects business intelligence platform73 CVEsnetweaver application server java68 CVEsbusinessobjects business intelligence45 CVEshana38 CVEssolution manager33 CVEsbusiness one31 CVEsinternet graphics server28 CVEs3d visual enterprise author27 CVEsbusinessobjects23 CVEsnetweaver abap21 CVEsnetweaver process integration21 CVEsnetweaver enterprise portal20 CVEss\/4hana20 CVEshana extended application services18 CVEssap basis18 CVEsbusiness objects business intelligence platform18 CVEscommerce cloud18 CVEsdisclosure management16 CVEshost agent15 CVEsenable now14 CVEsadaptive server enterprise14 CVEssap db13 CVEss4core13 CVEssap web application server12 CVEsnetweaver as abap12 CVEscustomer relationship management webclient ui12 CVEsabap platform12 CVEssupplier relationship management11 CVEssap kernel11 CVEsweb dispatcher11 CVEscommerce10 CVEscustomer relationship management10 CVEsnetweaver as abap business server pages10 CVEsinternet transaction server9 CVEsnetweaver application server for java9 CVEslandscape management8 CVEssql anywhere8 CVEsmaxdb8 CVEshana database8 CVEsmobile platform8 CVEshybris8 CVEscloud connector8 CVEstrex8 CVEsrfc library8 CVEss\/4 hana7 CVEsnetweaver as internet graphics server7 CVEserp7 CVEscrystal reports7 CVEsbusiness warehouse7 CVEsafaria7 CVEsbusiness connector7 CVEssapscore7 CVEsbusiness application software integrated solution6 CVEscustomer relationship management s4fnd6 CVEssapgui6 CVEsfiori client6 CVEsfinancial consolidation6 CVEsbasis6 CVEsbusiness planning and consolidation6 CVEsnetweaver knowledge management6 CVEsbusinessobjects edge6 CVEscontent server6 CVEspowerdesigner5 CVEsbw\/4hana5 CVEsgui for windows5 CVEscrystal reports server5 CVEssap r 35 CVEsnetweaver java application server5 CVEsadvanced business application programming platform kernel5 CVEss4fnd5 CVEsnetweaver as abap krnl64uc5 CVEsbusinessobjects web intelligence5 CVEsfiori launchpad4 CVEsnetweaver development infrastructure4 CVEsnetweaver as abap krnl64nuc4 CVEsnetweaver as abap kernel4 CVEsui4 CVEsbusiness client4 CVEsnetweaver abap application server4 CVEsenjoysap4 CVEsenterprise portal4 CVEsadvanced business application programming platform krnl64nuc4 CVEsfiori4 CVEsadvanced business application programming platform krnl64uc4 CVEsbusinessobjects bi platform4 CVEscommoncryptolib4 CVEsfocused run4 CVEscontact center4 CVEsj2ee engine4 CVEssaplpd4 CVEsapplication interface framework4 CVEsidentity management4 CVEsdiagnostics agent4 CVEsadvanced business application programming platform krnl32uc3 CVEsadvanced business application programming platform krnl32nuc3 CVEsnetwork interface router3 CVEsmanufacturing integration and intelligence3 CVEstreasury and risk management \(s4core\)3 CVEsnetweaver rfc sdk3 CVEsmanufacturing execution3 CVEsui53 CVEsbusinessobjects financial consolidation3 CVEssapsprint3 CVEsgui3 CVEsnetweaver portal3 CVEsenterprise financial services3 CVEshana db3 CVEserp central component3 CVEsplant connectivity3 CVEsgraphical user interface3 CVEssolution tools plug-in3 CVEssapcar3 CVEswork manager2 CVEsabap platform kernel2 CVEsaccess control2 CVEsauthenticator2 CVEsbank account management2 CVEsbanking services2 CVEsbanking services from sap2 CVEsbiller direct2 CVEsbusiness-one-hana-chef-cookbook2 CVEsbusiness intelligence development workbench2 CVEsbusiness intelligence promotion management application2 CVEsbusiness objects2 CVEsbusiness warehouse virtual comp2 CVEsbusinessobjects explorer2 CVEsbusinessobjects mobile2 CVEsbusinessobjects xi2 CVEscommerce backoffice2 CVEscommerce cloud \(accelerator payment mock\)2 CVEscommerce hycom2 CVEscontributor license agreement assistant2 CVEscrm - webclient ui2 CVEscustomer data cloud2 CVEsdata services2 CVEsdocument builder2 CVEsdocument management system2 CVEsdownload manager2 CVEse-commerce2 CVEsea-finserv2 CVEsemr unwired2 CVEsenterprise extension financial services2 CVEsenterprise threat detection2 CVEsenvironment health and safety2 CVEserp financial accounting2 CVEserp human capital management2 CVEsextended application services and runtime2 CVEsfiori launchpad \(news tile application\)2 CVEsgateway2 CVEshana web-based development workbench2 CVEshana xs2 CVEshuman capital management2 CVEsinfrabox2 CVEsinternet communication manager2 CVEsintroscope enterprise manager2 CVEsjava as2 CVEsmarketing2 CVEsmaster data governance2 CVEsmobile secure2 CVEsnetweaver business client2 CVEsnetweaver business client for html2 CVEsnetweaver business warehouse2 CVEsnetweaver guided procedures2 CVEsnetweaver knowledge management and collaboration \(kmc-cm\)2 CVEsnetweaver master data management2 CVEspoint of sale xpress server2 CVEspowerdesigner proxy2 CVEsprocess integration2 CVEsrouter2 CVEss\/4hana financial products subledger2 CVEssap basis component 6402 CVEssap basis component 7002 CVEssap gui2 CVEssap iq2 CVEssapcryptolib2 CVEssapssoext2 CVEsshared service framework2 CVEssimple diagnostics agent2 CVEsstudent life cycle management2 CVEssuccessfactors mobile2 CVEssupplier relationship management mdm catalog2 CVEsgrc process control1 CVEsdocument management services1 CVEsgui connector1 CVEsdmis1 CVEsguided procedures archive monitor1 CVEsdigital manufacturing1 CVEshana-client1 CVEshana cockpit1 CVEsdata intelligence1 CVEshana database explorer1 CVEscustomer relationship management s4crm1 CVEscustomer relationship management internet sales1 CVEshana sps091 CVEssso authentication library1 CVEsstrategic enterprise management1 CVEshcm fiori app my forms1 CVEshcm travel management1 CVEshealthcare industry solution1 CVEscustomer relationship management bbpcrm1 CVEswebclient ui framework1 CVEscustomer relationship management abap1 CVEscrystal reports for visual studio1 CVEsides ecc1 CVEsinformation steward1 CVEssuccessfactors1 CVEsinfrastructure1 CVEsinnovation management1 CVEswebdispatcher1 CVEscrm abap insights management1 CVEscontract lifecycle manager1 CVEsadvanced business application programming platform1 CVEsinventory manager1 CVEscontract accounting1 CVEsj2ee engine core1 CVEsj2ee engine server core1 CVEs\@sap\/xssec1 CVEskmc-bc1 CVEsknowledge warehouse1 CVEscomputing center management system monitoring1 CVEslandscape transformation1 CVEslandscape transformation replication server1 CVEsleasing1 CVEslt replication server1 CVEslumira server1 CVEsmanage reference structures1 CVEscompanion1 CVEscommerce webservices 2.01 CVEssupply chain management1 CVEsmarketing sapscore1 CVEsmarketing uicuan1 CVEssybase unwired platform online data proxy1 CVEsmaster data governance \(s4core\)1 CVEsmaster data governance \(s4fnd\)1 CVEsmaster data governance \(sap bs fnd\)1 CVEsmaster data governance for material data1 CVEsmaster data synchronization1 CVEscommerce data hub1 CVEsmaxdb odbc driver1 CVEsmessage server1 CVEsmobile infrastructure1 CVEscms services1 CVEsmobile platform sdk1 CVEsmobile sdk certificate provider1 CVEssystem landscape directory1 CVEsmysap business suite1 CVEscm services1 CVEscloud sdk1 CVEscloud platform integration1 CVEsnetweaver application server1 CVEscloud platform1 CVEsnetweaver application server abap kernel1 CVEsnetweaver application server abap krnl64nuc1 CVEsnetweaver application server abap krnl64uc1 CVEscloud-security-services-integration-library1 CVEscloud-security-client-go1 CVEsclinical task tracker1 CVEscla-assistant1 CVEschef business-one-cookbook1 CVEsccms agent1 CVEsccms \/ database monitor1 CVEscapacity leveling1 CVEsnetweaver as java for deploy service1 CVEsnetweaver bi content1 CVEstabone1 CVEstest data migration server1 CVEstransaction data pool1 CVEsnetweaver compare systems1 CVEsnetweaver composite application framework1 CVEsnetweaver design time repository1 CVEsnetweaver developer studio1 CVEsbusinessobjects enterprise1 CVEsbusinessobjects bw publisher service1 CVEsnetweaver exchange infrastructure \(bc-xi\)1 CVEstransportation management1 CVEsnetweaver internet communication manager \(kernel\)1 CVEsnetweaver internet communication manager \(krnl32nuc\)1 CVEsnetweaver internet communication manager \(krnl32uc\)1 CVEsnetweaver internet communication manager \(krnl64nuc\)1 CVEsnetweaver internet communication manager \(krnl64uc\)1 CVEsnetweaver internet transaction server1 CVEsnetweaver j2ee engine1 CVEsnetweaver java1 CVEsbusinessobjects analysis1 CVEsnetweaver java web application1 CVEsnetweaver java web container and http service engine1 CVEsbusiness workflow1 CVEstreasury and risk management1 CVEsnetweaver knowledge management and collaboration \(kmc-wpc\)1 CVEsnetweaver knowledge management configuration service1 CVEsnetweaver knowledge management xml forms1 CVEsnetweaver logviewer1 CVEstreasury and risk management \(ea-finserv\)1 CVEsnetweaver master data management server1 CVEsnetweaver nw041 CVEsnetweaver nw04s1 CVEsbusiness warehouse universal data integration1 CVEsbusiness server pages1 CVEsbusiness one on hana1 CVEsnetweaver software lifecycle manager1 CVEsnetweaver solution manager1 CVEsnetweaver system landscape directory1 CVEsbusiness one license service api1 CVEsoil \%\/ gas1 CVEsoil industry solution traders and schedulers workbench1 CVEsopen hub service1 CVEsopenui51 CVEsorientdb1 CVEspayment engine1 CVEspayroll process1 CVEspeople profile1 CVEspermit to work1 CVEsbusiness one client1 CVEsadvanced business application programming1 CVEsportfolio and project management1 CVEsbusiness one 2005-a1 CVEsadminadapter1 CVEsprint and output management1 CVEsprivileges1 CVEsadaptive server enterprise cockpit1 CVEsprocess integration \(pgp module - business-to-business add on\)1 CVEsprocess monitoring infrastructure1 CVEsproduction planning and control1 CVEsprofile maintenance1 CVEsproject system1 CVEsquality management1 CVEsr\/3 enterprise1 CVEsr\/3 enterprise retail1 CVEsbusiness object processing framework for abap1 CVEsadaptive server enterprise backup server1 CVEsbusiness intelligence platform1 CVEss4coreop1 CVEsbrazil1 CVEss4hana sales1 CVEsbi universal data integration1 CVEss\/4 hana fiori ui for general ledger accounting1 CVEsbi launchpad1 CVEss\/4hana defense \& security1 CVEss\/4hana finance1 CVEsui5 java1 CVEss\/4hana for financial products subledger1 CVEss\/4hana uiapfi701 CVEss\/4hana uis4h1 CVEssaf-t framework1 CVEssap-xssec1 CVEssap aba1 CVEssap as abap\(dmis\)1 CVEsbex web java runtime export web service1 CVEsui infra1 CVEsupgrade tools1 CVEsbasis communication services1 CVEsuser interface technology1 CVEsvendor master hierarchy1 CVEsbank analyzer1 CVEssap kernel krnl32nuc1 CVEssap kernel krnl32uc1 CVEssap kernel krnl64nuc1 CVEssap kernel krnl64uc1 CVEssap message server1 CVEssap netweaver1 CVEssap netweaver application server java1 CVEsbank\/cfm1 CVEssap r 3 web application server demo1 CVEssap s4 hana\(dmis\)1 CVEssap solution manager system1 CVEsbackground processing1 CVEsase database platform1 CVEssapcar archive tool1 CVEssapconsole1 CVEsadaptive extensions1 CVEssapdba1 CVEsapplication server java1 CVEsapplication server1 CVEssaposcol1 CVEsapplication interface1 CVEssapseculib1 CVEssapsetup1 CVEsanalysis for microsoft office1 CVEsweb dynpro1 CVEssaptmui1 CVEssapui51 CVEssapui5 library1 CVEsscimono1 CVEsserver core1 CVEssetup1 CVEsweb dynpro abap1 CVEsenhancement package1 CVEsenterprise central component1 CVEsenterprise extension defense forces \& public security1 CVEsweb services tool1 CVEsenable now wpb manager hana1 CVEsenterprise performance management1 CVEsenable now wpb manager ce1 CVEsenterprise resource planning1 CVEssld registration1 CVEssoftware deployment manager1 CVEsepbc1 CVEsepbc21 CVEsenable now wpb manager1 CVEserp \(ea-finserv\)1 CVEserp \(s4core\)1 CVEsenable now manager1 CVEserp client for e-bilanz1 CVEserp defense forces and public security1 CVEssoftware provisioning manager1 CVEserp financials information system1 CVEserp hcm1 CVEsagentry sdk1 CVEserp localization for cee countries1 CVEserp sales1 CVEsadvanced planning and optimization1 CVEsfi manager self-service1 CVEsenable now enable now consump del1 CVEsfinancial consolidation cube designer1 CVEsfinancial consolidation cube designer bobj eades1 CVEsemployee self service1 CVEsfiori apps 2.0 for travel management in sap erp1 CVEsemarsys sdk1 CVEsfiori front end server1 CVEse-recruiting1 CVEssourcing1 CVEsdynamic tier1 CVEsadvanced business application programming server1 CVEsgeneric market data1 CVEsgovernance risk and compliance1 CVEsdynamic authorization management1 CVEs

Recent Vulnerabilities

View all 1,571
CVE-2026-34264MEDIUM 6.5

During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.

CVE-2026-34262MEDIUM 5.0

Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer

CVE-2026-27679MEDIUM 6.5

Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability has a high impact on integrity, while confidentiality and availability are not impacted.

CVE-2026-24314MEDIUM 4.3

Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which would otherwise be restricted. This could cause low impact on confidentiality of the application while integrity and availability are not impacted.

CVE-2026-24328MEDIUM 6.1

SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.

CVE-2026-24327MEDIUM 4.3

Due to missing authorization check in SAP Strategic Enterprise Management (Balanced Scorecard in Business Server Pages), an authenticated attacker could access information that they are otherwise unauthorized to view. This leads to low impact on confidentiality and no effect on integrity or availability.

CVE-2026-24326MEDIUM 4.3

Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker with user privileges could call remote-enabled function modules to do direct update on standard SAP database table . This results in low impact on integrity, with no impact on confidentiality or availability of the application.

CVE-2026-24325MEDIUM 4.8

SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an admin user to inject malicious JavaScript into a website and the injected script gets executed when the user visits the compromised page.This vulnerability has low impact on confidentiality and integrity of the data. There is no impact on the availability of the application.

CVE-2026-24324MEDIUM 6.5

SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause the Content Management Server (CMS) to crash, rendering the CMS partially or completely unavailable and resulting in the denial of service of the Content Management Server (CMS). Successful exploitation impacts system availability, while confidentiality and integrity remain unaffected.

CVE-2026-24323MEDIUM 6.1

The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sanitized. When a victim accesses a crafted URL, the injected script is executed in the victim�s browser, leading to a low impact on confidentiality and integrity, and no impact on the availability of the application.

CVE-2026-24322HIGH 7.7

SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing sensitive information to be disclosed. This vulnerability has a high impact on confidentiality and does not affect integrity or availability.

CVE-2026-24321MEDIUM 5.3

SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via the front-end. This vulnerability has a low impact on confidentiality and does not affect integrity and availability.

CVE-2026-24320LOW 3.1

Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker could exploit logical errors in memory management by supplying specially crafted input containing unique characters, which are improperly converted. This may result in memory corruption and the potential leakage of memory content. Successful exploitation of this vulnerability would have a low impact on the confidentiality of the application, with no effect on its integrity or availability.

CVE-2026-24319MEDIUM 5.8

In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information could potentially lead to unauthorized operations within the B1 environment, including modification of company data. This issue results in a high impact on confidentiality and integrity, with no impact on availability.

CVE-2026-24312MEDIUM 5.2

An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensitive function to execute unauthorized, high-privilege actions. This has a high impact on data integrity, with low impact on confidentiality and no impact on availability of the application.

CVE-2026-23689HIGH 7.7

Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.

CVE-2026-23688MEDIUM 4.3

SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on integrity, confidentiality and availability are not impacted.

CVE-2026-23687HIGH 8.8

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information, unauthorized access to sensitive user data and potential disruption of normal system usage.

CVE-2026-23686LOW 3.4

Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configuration, allowing manipulation of application-controlled settings. Successful exploitation leads to a low impact on integrity, while confidentiality and availability remain unaffected.

CVE-2026-23685MEDIUM 4.4

Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If processed by the application, this content could trigger unintended behavior during internal logic execution, potentially causing a denial of service. Successful exploitation results in a high impact on availability, while confidentiality and integrity remain unaffected.

CVE-2026-23684MEDIUM 5.9

A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart entry being created with erroneous product value which could be checked out. This leads to high impact on data integrity, with no impact on data confidentiality or availability of the application.

CVE-2026-23681MEDIUM 4.3

Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could invoke specific function modules to retrieve information about the system and its configuration. This disclosure of the system information could assist the attacker to plan subsequent attacks. This vulnerability has a low impact on the confidentiality of the application, with no effect on its integrity or availability.

CVE-2026-0509CRITICAL 9.6

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentiality of the application.

CVE-2026-0508HIGH 7.3

The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the application. Upon successful exploitation, the victim may click on this malicious URL, resulting in an unvalidated redirect to the attacker-controlled domain and subsequently download the malicious content. This vulnerability has a high impact on the confidentiality and integrity of the application, with no effect on the availability of the application.

CVE-2026-0505MEDIUM 6.1

The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could result in unvalidated redirection to attacker-controlled websites, leading to a low impact on confidentiality and integrity, and no impact on the availability of the application.