SAP May 2026 HotNews — CVE-2026-34263 Commerce Cloud Unauthenticated RCE & CVE-2026-34260 S/4HANA Enterprise Search SQL Injection (CVSS 9.6) — Threadlinqs Intelligence
As of 2026-05-30, SAP May 2026 HotNews — CVE-2026-34263 Commerce Cloud Unauthenticated RCE & CVE-2026-34260 S/4HANA Enterprise Search SQL Injection (CVSS 9.6) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-0501 · Severity: CRITICAL · CVSS: 9.6 · Status: MONITORING · Category: VULNERABILITY
SAP released its May 2026 Security Patch Day on May 12, 2026, addressing 15 security notes including two HotNews CRITICAL vulnerabilities both rated CVSS 9.6. CVE-2026-34263 is an unauthenticated
SAP's May 2026 Security Patch Day, released on May 12, 2026, addressed 15 security notes across multiple enterprise SAP products, with two HotNews vulnerabilities both scoring CVSS 9.6 representing the most critical exposure.
CVE-2026-34263 — SAP Commerce Cloud Unauthenticated Remote Code Execution (SAP Note 3733064)
This critical flaw resides in SAP Commerce Cloud's Spring Security configuration. The root cause is an overly permissive security rule set with improper rule ordering — a classic Spring Security misconfiguration where more permissive rules are evaluated before restrictive ones, causing authentication checks to be bypassed entirely. An unauthenticated remote attacker can reach the misconfigured endpoint to upload malicious configuration files and inject arbitrary code, resulting in remote code execution (RCE) with the privileges of the Commerce Cloud process. Affected product lines include HY_COM 2205, COM_CLOUD 2211, and COM_CLOUD 2211-JDK21. The CVSS vector (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) reflects a network-accessible attack surface with low complexity, no authentication requirement, and full compromise of confidentiality, integrity, and availability with changed scope — meaning successful exploitation can affect components beyond the targeted SAP system, including connected ERP backends. The CWE-459 (Incomplete Cleanup) classification indicates that residual state from incomplete security enforcement leaves the authentication bypass exploitable.
SAP Commerce Cloud (formerly SAP Hybris) is a widely deployed enterprise e-commerce platform used by large retailers and B2B organizations globally. Successful exploitation of this RCE would allow attackers to fully compromise the application server, access customer PII and payment processing infrastructure, and pivot to connected SAP ERP systems via trusted internal network paths. The Hybris Administration Console (HAC) is the primary attack surface — its Groovy scripting engine and ImpEx import functionality are high-value targets once the authentication bypass is achieved.
CVE-2026-34260 — SAP S/4HANA Enterprise Search SQL Injection (SAP Note 3724838)
This flaw affects SAP S/4HANA's Enterprise Search for ABAP component across SAP_BASIS versions 751 through 758 and 816. The root cause is improper or missing input validation — user-controlled search input is directly concatenated into ABAP Open SQL queries without sanitization, creating a classic SQL injection vulnerability. An authenticated attacker with low-privilege access can inject malicious SQL statements through the Enterprise Search interface to manipulate database queries. Because the affected code path is read-only, integrity is not impacted; however, confidentiality and availability are rated high — meaning an attacker can exfiltrate sensitive ERP data spanning financial records, HR information, customer accounts, and business-critical master data, and cause denial-of-service conditions in the Enterprise Search component through resource-exhausting queries.
SAP S/4HANA is the core ERP platform for thousands of large enterprises. Enterprise Search is a cross-module search functionality, meaning the SQL injection surface potentially spans multiple sensitive business domains including FI (Finance), HR (HCM), SD (Sales and Distribution), and MM (Materials Management).
Context and Urgency
Both vulnerabilities were patched on SAP's standard monthly patch day with no evidence of active exploitation at time of disclosure. However, given the severity (CVSS 9.6), network-accessible attack vectors, and the historical pattern of threat actors targeting SAP systems — CISA has added 14+ SAP security flaws to its Known Exploited Vulnerabilities catalog in prior years, with ransomware actors specifically targeting unpatched SAP instances — rapid patching is essential. Onapsis Research Labs, a leading SAP security research firm, published independent analysis on May 12, 2026, confirming technical severity. Organ
Weaknesses (CWE)
CWE-459, CWE-89
Target sectors: retail, e-commerce, financial, manufacturing, healthcare, energy, government, professional-services, automotive, consumer-goods
Target regions: Global, North America, Europe, Asia Pacific, Middle East
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-34263, CVE-2026-34260, T1190, T1059, T1505, T1068, T1211, T1212, T1082, T1046, T1213, T1005