medium2026-09-08SAP S/4HANA — Advanced Payment ManagementCVE-2026-76960

Cross-Site Request Forgery in Advanced Payment Management (2 of 3)

SAP S/4HANA

Our Take

See note 3371336. Apply all three Advanced Payment Management CSRF notes in the same transport cycle.

Vulnerability Detail

Second Cross-Site Request Forgery vulnerability in SAP S/4HANA Advanced Payment Management. Different endpoint from CVE-2026-76961 but same application module.

Patch Action

Apply SAP Note 3365276 together with notes 3371336 and 3365311. Verify affected S/4HANA release in the official SAP Note.

Patch Info

CVSS Score

4.3

SAP Note

3365276

CVE

CVE-2026-76960

Published

2026-09-08

← All patches