Exploitation timeline
Threadlinqs has recorded 11 SAP SE CVEs published between and . The busiest month was 2026-07 (7 new CVEs). None of them is listed in CISA KEV yet.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 11 of 11 tracked SAP SE CVEs.
- CVE-2026-40128critical 9EPSS 0.5%
- CVE-2026-44748critical 9.9EPSS 0.2%
- CVE-2026-34263critical 9.6EPSS 0%
- CVE-2026-34260critical 9.6EPSS 0%
- CVE-2026-44747critical 9.9
- CVE-2026-27690critical 9.1
- CVE-2026-44761critical 9.1
- CVE-2026-0487high 8.4
- CVE-2026-44752high 8.2
- CVE-2026-44745high 8.1
- CVE-2026-58233high 7.6
Products affected
Threadlinqs normalises CPE and CNA product records across all 11 CVEs; 10 distinct SAP SE products are affected. The most frequently affected:
- SAP Approuter 2 CVEs
- SAP Change and Transport System Attach Tool (ctsattach) 1 CVE
- SAP Commerce Cloud 1 CVE
- SAP Commerce cloud configuration 1 CVE
- SAP NetWeaver AS ABAP and ABAP Platform 1 CVE
- SAP NetWeaver Application Server ABAP 1 CVE
- SAP NetWeaver Application Server Java (Web Container) 1 CVE
- SAP NetWeaver Application Server Java(Configuration Wizard) 1 CVE
- SAP S/4HANA (SAP Enterprise Search for ABAP) 1 CVE
- SAProuter on Microsoft Windows 1 CVE
Threat activity
8 tracked threat campaigns reference SAP SE products or exploit SAP SE CVEs:
- SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities (CVE-2026-58231, CVSS 10.0)CRITICAL
- Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and Cloudflare/MongoDB/Broker Credentials Offered for €5,000HIGH
- CVE-2026-44747: Critical Memory Corruption in SAP NetWeaver Application Server ABAP (CVSS 9.9)CRITICAL
- SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761)CRITICAL
- SAP July 2026 Patch Day: Critical Memory Corruption in NetWeaver ABAP (CVE-2026-44747, CVSS 9.9) Among 16 Security NotesCRITICAL
- SAP Patches CVSS 9.9 NetWeaver ABAP Out-of-Bounds Write Flaw (CVE-2026-44747), Plus Critical Approuter and Commerce Cloud BugsCRITICAL
- CVE-2026-44748: XML Signature Wrapping in SAP NetWeaver AS ABAP SAML Authentication (CVSS 9.9)CRITICAL
- SAP May 2026 HotNews — CVE-2026-34263 Commerce Cloud Unauthenticated RCE & CVE-2026-34260 S/4HANA Enterprise Search SQL Injection (CVSS 9.6)CRITICAL
How to prioritise SAP SE patching
This order follows the data Threadlinqs holds for SAP SE, not a generic severity checklist:
- No SAP SE CVE is in CISA KEV yet, so rank by exploit probability instead.
- Outside KEV, the highest EPSS scores are CVE-2026-40128 (0.5%), CVE-2026-44748 (0.2%), CVE-2026-34263 (0%).
- 7 CVEs score Critical and 4 High on CVSS v3 (maximum 9.9, average 9); sequence these after KEV and high-EPSS items.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.