medium2026-09-08SAP S/4HANA — Advanced Payment ManagementCVE-2026-76961

Cross-Site Request Forgery in Advanced Payment Management (1 of 3)

SAP S/4HANA

Our Take

Three CSRF notes in the same payment management module in one release suggests a systematic security review found multiple unprotected endpoints. Apply all three together.

Vulnerability Detail

Cross-Site Request Forgery vulnerability in SAP S/4HANA Advanced Payment Management. One of three CSRF notes released this month for the same application module.

Patch Action

Apply SAP Note 3371336 together with notes 3365276 and 3365311 to remediate all three CSRF vectors in Advanced Payment Management. Verify affected S/4HANA release in the official SAP Note.

Patch Info

CVSS Score

4.3

SAP Note

3371336

CVE

CVE-2026-76961

Published

2026-09-08

← All patches