medium2026-05-12SAP NetWeaverCVE-2026-40129
Code Injection in SAP Application Server ABAP
SAP Application Server ABAP
Our Take
Code injection is always worth addressing — the medium CVSS reflects limited exploit conditions, not low intrinsic risk. Next window.
Vulnerability Detail
Code injection vulnerability in SAP Application Server ABAP affecting a broad range of BASIS versions. Allows an attacker under specific conditions to inject and execute arbitrary code.
Patch Action
Apply SAP Note 3735359.
Affected Versions
SAP_BASIS 740–816
Patch Info