2026 CVE Vulnerabilities

47,554 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-66774LOW3.7SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this ...
CVE-2026-66773MEDIUM5.9A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data i...
CVE-2026-66772MEDIUM4.3SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on cer...
CVE-2026-66771MEDIUM6.1SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted applicatio...
CVE-2026-66770MEDIUM6.3Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL...
CVE-2026-66764MEDIUM4.3Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated user...
CVE-2026-66763HIGH7.9SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects usi...
CVE-2026-66761MEDIUM4.3SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could s...
CVE-2026-66760MEDIUM6.4SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges...
CVE-2026-58248MEDIUM6.5SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a speci...
CVE-2026-58247MEDIUM5.3SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This coul...
CVE-2026-58245LOW3.8SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of th...
CVE-2026-58244MEDIUM4.3SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain applicati...
CVE-2026-58243HIGH8.8SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attack...
CVE-2026-58241MEDIUM4.2SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privi...
CVE-2026-58239LOW3.7SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send ...
CVE-2026-58238MEDIUM5.9SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could...
CVE-2026-58237MEDIUM5.9WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with l...
CVE-2026-58236MEDIUM5.5SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing securit...
CVE-2026-58235MEDIUM6.3SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer...
CVE-2026-58230HIGH7SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated att...
CVE-2026-44765HIGH7.3Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated...
CVE-2026-44764HIGH7.3Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated...
CVE-2026-44763HIGH7.6SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation...
CVE-2026-44762LOW3.7SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now