Threadlinqs IntelligenceStart free

Vendor10 products tracked

SAP SE vulnerabilities & exploitation

As of 2026-10-05, Threadlinqs tracks 11 SAP SE CVEs, 0 in the CISA Known Exploited Vulnerabilities catalog, linked to 8 tracked threat campaigns.

CVEs
11Since 2026
CISA KEV
00% of CVEs
Critical
7CVSS v3 9.0+
Avg CVSS
9/10Max 9.9
Threats
8Linked campaigns
Actors
0None attributed

Data as of:

Exploitation timeline

Threadlinqs has recorded 11 SAP SE CVEs published between and . The busiest month was 2026-07 (7 new CVEs). None of them is listed in CISA KEV yet.

Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 11 of 11 tracked SAP SE CVEs.

Products affected

Threadlinqs normalises CPE and CNA product records across all 11 CVEs; 10 distinct SAP SE products are affected. The most frequently affected:

  • SAP Approuter 2 CVEs
  • SAP Change and Transport System Attach Tool (ctsattach) 1 CVE
  • SAP Commerce Cloud 1 CVE
  • SAP Commerce cloud configuration 1 CVE
  • SAP NetWeaver AS ABAP and ABAP Platform 1 CVE
  • SAP NetWeaver Application Server ABAP 1 CVE
  • SAP NetWeaver Application Server Java (Web Container) 1 CVE
  • SAP NetWeaver Application Server Java(Configuration Wizard) 1 CVE
  • SAP S/4HANA (SAP Enterprise Search for ABAP) 1 CVE
  • SAProuter on Microsoft Windows 1 CVE

Threat activity

8 tracked threat campaigns reference SAP SE products or exploit SAP SE CVEs:

How to prioritise SAP SE patching

This order follows the data Threadlinqs holds for SAP SE, not a generic severity checklist:

  • No SAP SE CVE is in CISA KEV yet, so rank by exploit probability instead.
  • Outside KEV, the highest EPSS scores are CVE-2026-40128 (0.5%), CVE-2026-44748 (0.2%), CVE-2026-34263 (0%).
  • 7 CVEs score Critical and 4 High on CVSS v3 (maximum 9.9, average 9); sequence these after KEV and high-EPSS items.

About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.