Real SAP Security Notes from SAP Patch Tuesday May 12, 2026. CVSS scores and SAP Note IDs are factual references — all other content is editorial summary, not professional security advice. Patch timing is the responsibility of your security team based on your environment and SAP's official guidance.

May 2026 · 15 notes

Patch Intelligence

SAP Security Patches

Every SAP Security Note from Patch Tuesday, ranked by what actually matters to your landscape. Tier 1 products are in almost every SAP shop — missing a patch there is career-ending for BASIS admins.

2

Critical

1

High

11

Medium

1

Low

Severity
Timing

Tier 1 · Always covered

7 patches

Products in virtually every SAP environment. Patch these first, every month.

T12026-05-12
SAP S/4HANA

SQL Injection in SAP S/4HANA Enterprise Search

Unsanitised user input is concatenated directly into SQL queries in the Enterprise Search component, allowing an authenticated attacker to inject arbitrary SQL statements. Impact is primarily on confidentiality and availability — unauthorised database access and information disclosure are possible.

🔴Patch immediately
#3724838CVSS 9.6
T12026-05-12
SAP NetWeaver

OS Command Injection in SAP NetWeaver Application Server ABAP

OS command injection vulnerability in SAP NetWeaver AS ABAP affecting an extremely broad range of BASIS versions. Allows execution of operating system commands under specific conditions.

#3730019CVSS 6.5
T12026-05-12
SAP S/4HANA

Missing Authorization Check in SAP S/4HANA Condition Maintenance

Missing authorisation check in the Condition Maintenance functionality of S/4HANA allows an authenticated user to access or modify pricing condition data beyond their intended permissions.

#3718083CVSS 6.3
T12026-05-12
SAPUI5

Content Spoofing in SAPUI5 Search UI

Content spoofing vulnerability in the SAPUI5 Search UI component allows an attacker to craft URLs that display misleading content within the search interface, potentially used as a phishing vector.

#3726583CVSS 4.7
T12026-05-12
SAP NetWeaver

Reflected XSS in SAP NetWeaver Application Server ABAP

Reflected cross-site scripting vulnerability in SAP NetWeaver AS ABAP. An attacker can craft a URL that, when accessed by a victim, executes scripts in the browser context of the victim.

#3728690CVSS 4.7
T12026-05-12
SAP NetWeaver

Code Injection in SAP Application Server ABAP

Code injection vulnerability in SAP Application Server ABAP affecting a broad range of BASIS versions. Allows an attacker under specific conditions to inject and execute arbitrary code.

#3735359CVSS 4.3
T12026-05-12
SAP HANA

SQL Injection in SAP HANA HDI Deploy Library

SQL injection vulnerability in the SAP HANA Deployment Infrastructure (HDI) Deploy Library. Limited exploit conditions reduce severity to low.

#3726962CVSS 3.4

Tier 2 · Covered when notable

7 patches

Products with real deployments that have something worth acting on this month.

T22026-05-12
SAP Commerce Cloud

Missing Authentication Check in SAP Commerce Cloud Configuration Upload

An overly permissive Spring Security configuration with incorrect rule ordering allows unauthenticated users to access the configuration upload functionality. An attacker can upload malicious configuration that triggers code injection, resulting in arbitrary server-side code execution. The fix requires a rebuild and redeployment of the affected application.

🔴Patch immediately
#3733064CVSS 9.6
T22026-05-12
SAP F&R

OS Command Injection in SAP Forecasting & Replenishment

Insufficient control over operating system commands in five function modules allows an authenticated attacker with administrative authorisations to execute arbitrary OS commands. The affected functions are not remote-enabled, but exploitation by a privileged user has high impact on confidentiality, integrity, and availability.

#3732471CVSS 8.2
T22026-05-12
SAP NetWeaver

Reflected XSS in Business Server Pages TAF_APPLAUNCHER

Reflected cross-site scripting vulnerability in the TAF_APPLAUNCHER Business Server Page used by Component-Based Test Automation. An attacker can craft a URL that, when accessed by a victim, executes scripts in the victim's browser context.

#3727717CVSS 6.1
T22026-05-12
SAP BusinessObjects

Cross-Site Request Forgery in SAP BusinessObjects BI Platform

A CSRF vulnerability in the BusinessObjects BI Platform that could allow an attacker to trick an authenticated user into performing unintended actions.

#3667593CVSS 5.4
T22026-05-12
SAP Commerce Cloud

Improper Certificate Validation in SAP Commerce Cloud Log4j Component

Improper certificate validation in the Apache Log4j dependency shipped with SAP Commerce Cloud could allow man-in-the-middle attacks against outbound HTTPS connections from the platform.

#3716450CVSS 4.8
T22026-05-12
SAP Financial Consolidation

Denial of Service in SAP Financial Consolidation

A denial of service vulnerability in SAP Financial Consolidation that could be exploited by an authenticated user to impact availability of the system.

#3713521CVSS 4.3
T22026-05-12
SAP S/4HANA

Missing Authorization Check in SAP Incentive & Commission Management

Missing authorisation check in the Incentive & Commission Management functionality allows an authenticated attacker to access or modify incentive-related data without proper permissions.

#3718508CVSS 4.3

Previous months

Apr 2026Mar 2026Feb 2026Jan 2026Dec 2025