- CVE-2026-44756 CRITICAL CVSS 10.0 -
NVD: A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. NVD: Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. NVD: Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 10.0 (CRITICAL); EPSS percentile 25; sources: NVD.
- CVE-2026-58240 CRITICAL CVSS 9.8 -
NVD: SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. NVD: An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the...
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 9.8 (CRITICAL); EPSS percentile 27; sources: NVD.
- CVE-2026-76969 CRITICAL CVSS 9.4 -
NVD: @sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. NVD: An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. NVD: Successful exploitation can result in a high impact on availability and integrity of the application.
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 9.4 (CRITICAL); EPSS percentile 22; sources: NVD.
- CVE-2026-66768 CRITICAL CVSS 9.0 -
NVD: SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. NVD: A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. NVD: This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system.
An attacker may be able to run code or commands on affected systems; CVSS 9.0 (CRITICAL); EPSS percentile 25; sources: NVD.
- CVE-2026-86510 HIGH CVSS 8.6 -
NVD: A vulnerability has been found in D-Link DIR-822A A_101. NVD: Affected is the function tunnel_set_params of the component L2TP Control Message Parser. NVD: Such manipulation leads to out-of-bounds write.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.6 (HIGH); EPSS percentile 39; sources: NVD.
- CVE-2026-86509 HIGH CVSS 8.6 -
NVD: A flaw has been found in D-Link DIR-895L A1_102b07. NVD: This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. NVD: This manipulation causes stack-based buffer overflow.
The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure; CVSS 8.6 (HIGH); EPSS percentile 37; sources: NVD.
- CVE-2026-76958 HIGH CVSS 8.5 -
NVD: SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. NVD: An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. NVD: Successful exploitation could allow the attacker to read sensitive file contents from the server and expose them through monitoring or logging output, resulting in a high impact on confidentiality.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.5 (HIGH); EPSS percentile 13; sources: NVD.
- CVE-2026-76967 HIGH CVSS 7.8 -
NVD: SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. NVD: An attacker with low privileges on the local system could replace this data with specially crafted content. NVD: When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user.
An attacker may be able to run code or commands on affected systems; CVSS 7.8 (HIGH); EPSS percentile 12; sources: NVD.
- CVE-2026-66767 HIGH CVSS 7.7 -
NVD: SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing... NVD: Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 7.7 (HIGH); EPSS percentile 18; sources: NVD.
- CVE-2026-76968 MEDIUM CVSS 6.5 -
NVD: SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in... NVD: This disclosed information could potentially be used to facilitate further attacks. NVD: This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.
An attacker may be able to access information that should not be exposed; CVSS 6.5 (MEDIUM); EPSS percentile 14; sources: NVD.
- CVE-2026-44766 MEDIUM CVSS 6.5 -
NVD: SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. NVD: This could allow the user to access sensitive information, resulting in high impact on confidentiality, with no impact on integrity and availability of the application.
An attacker may be able to access information that should not be exposed; CVSS 6.5 (MEDIUM); EPSS percentile 14; sources: NVD.
- CVE-2026-76971 MEDIUM CVSS 6.5 -
NVD: Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. NVD: If processed by the application, this behavior could be combined with XML/XSL processing to enable execution of scripts. NVD: Successful exploitation could result in a low impact on the confidentiality, integrity, and availability of the application.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 6.5 (MEDIUM); EPSS percentile 4; sources: NVD.
- CVE-2026-76959 MEDIUM CVSS 4.6 -
NVD: SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. NVD: If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. NVD: This results in a low impact on confidentiality and integrity.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 4.6 (MEDIUM); EPSS percentile 0; sources: NVD.
- CVE-2026-76977 MEDIUM CVSS 4.3 -
NVD: SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. NVD: An unauthenticated attacker could host a malicious page to bypass framing restrictions. NVD: If an authenticated victim visits the attacker's page and interacts with it, the attacker could trick the victim into performing unintended actions, resulting in a low impact on integrity.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 4.3 (MEDIUM); EPSS percentile 13; sources: NVD.
- CVE-2026-76962 MEDIUM CVSS 4.3 -
NVD: SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. NVD: An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. NVD: This results in a low impact on availability.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 4.3 (MEDIUM); EPSS percentile 10; sources: NVD.
- CVE-2026-76963 MEDIUM CVSS 4.3 -
NVD: Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. NVD: Successful exploitation could result in exposure of security relevant settings and internal system details, resulting in low impact on confidentiality while integrity and availability remain unaffected.
An attacker may access resources that should require stronger authorization; CVSS 4.3 (MEDIUM); EPSS percentile 6; sources: NVD.
- CVE-2026-76961 LOW CVSS 3.5 -
NVD: SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. NVD: If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. NVD: This results in a low impact on confidentiality and integrity.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 3.5 (LOW); EPSS percentile 1; sources: NVD.
- CVE-2026-76960 LOW CVSS 3.5 -
NVD: SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. NVD: If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. NVD: This results in a low impact on confidentiality and integrity.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 3.5 (LOW); EPSS percentile 1; sources: NVD.
- CVE-2026-82710 LOW CVSS 2.3 -
NVD: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control sequences into the output of mix usage_rules.search_docs. NVD: mix usage_rules.search_docs searches Hex documentation through search.hexdocs.pm, which indexes the documentation of every published package, and prints the matching results (title, package, type, doc reference, and highlighted snippets) to the terminal. NVD: The formatter in Mix.Tasks.UsageRules.SearchDocs interpolated those publisher-controlled fields verbatim, neutralizing no terminal control characters; the only transform it applied adds escape sequences rather than removing them.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.3 (LOW); EPSS percentile 34; sources: NVD, OSV.
- CVE-2026-58234 LOW CVSS 2.2 -
NVD: SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. NVD: Successful exploitation results in low impact on availability with no impact on confidentiality and integrity.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.2 (LOW); EPSS percentile 12; sources: NVD.