SAP Security Notes, May 2026

Through services such as SAP Security Assessment, Inprosec helps its clients improve the security levels of their SAP systems.

 

May 2026 Notes

Monthly Summary and Highlights

This month, the total number of notes was 15 (all new, with no updates), 5 fewer than in April. Two Hot News notes were published this month, one more than in the previous period. Regarding high-severity notes, there was 1, the same number as in April. Medium and low-severity notes will not be reviewed, so we will provide details on a total of 3 notes (all those with a CVSS score of 7 or higher).
We have a total of 15 notes for the entire month (all 15 are new and there are no updates from previous months).
We will review in detail a total of 3 notes, all of them high-severity and Hot News:
This month, the most common category was once again “Missing Authorization Check” (4/15 in the Patch Day).
The chart shows the classification of May’s notes, as well as the evolution and classification of the previous five months (considering only SAP Security Tuesday / Patch Day notes).

Full Details

The full details of the most relevant notes are as follows (in English):

Reference Links

References from SAP and Onapsis (May):

Affected Resources

The complete list of affected systems/components is as follows:

Did you like it?

Share it on social media!

Leave a Reply

Your email address will not be published. Required fields are marked *

Fill out this field
Fill out this field
Please enter a valid email address.
You need to agree with the terms to proceed

Categories

Calendar of posts

Our services

keyboard_arrow_up