sap has 17 CVEs on record between 2022 and 2026. Disclosure cadence is accelerating: 13 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 11. The median CVSS is 5.9 (medium), with 5 rated critical. 12% have been exploited in the wild — well above the 1% corpus average, so sap flaws are worth patching on sight. Most affected products: approuter (13), netweaver (2), enable_now_manager (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 12% vs 1% corpus
- Median CVSS
- 5.9
- Publish → KEV
- —(2)
- Last 90 days
- 13 prev 0
Products
- approuter 13
- netweaver 2
- enable_now_manager 1
- github.com/sap/cloud-security-client-go 1
Worst active — by depth score
CVE-2025-31324Critical· 10.0SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system100CVE-2025-42999Critical· 9.1SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availabili…83CVE-2026-27690Critical· 9.1Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization50CVE-2023-50422Critical· 9.1Improper Privilege Management in github.com/sap/cloud-security-client-go50CVE-2022-35293Critical· 9.1Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account50
sap vulnerabilities
CVEs affecting sap, newest first. Open any entry for full detail, references, and exploit status.
17 CVEsRSS
CVE-2026-66778Medium· 5.3SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components
SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to informatio…
CVE-2026-66777Medium· 5.9SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations
SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the required conditions, an attacker with low privileges could send specially crafted request…
CVE-2026-66776Medium· 5.9SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions
SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity c…
CVE-2026-66775Medium· 4.3SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default
SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link and trick a victim into following it. Successful exploitation could allo…
CVE-2026-66774Low· 3.7SAP Approuter does not consistently handle certain error conditions
SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on conditions outside the…
CVE-2026-66761Medium· 4.3SAP Approuter does not enforce sufficient flow control in certain functionality
SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact o…
CVE-2026-66760Medium· 6.4SAP Approuter does not correctly validate client certificates in certain callback flows
SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check…
CVE-2026-58239Low· 3.7SAP Approuter does not sufficiently validate tenant context in inbound requests
SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful ex…
CVE-2026-58238Medium· 5.9SAP Approuter does not sufficiently handle certain requests under specific conditions
SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specif…
CVE-2026-58237Medium· 5.9WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality
WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could allow the attacker…
CVE-2026-58230High· 7.0SAP Approuter does not sufficiently validate certain token content under specific configurations
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlle…
CVE-2026-44745High· 8.1SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could …
CVE-2026-27690Critical· 9.1Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user response…
CVE-2025-42999Critical· 9.1CISA KEVSAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availabili…
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availabili…
CVE-2025-31324Critical· 10.0CISA KEVPoCSAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could signifi…
CVE-2023-50422Critical· 9.1Improper Privilege Management in github.com/sap/cloud-security-client-go
Improper Privilege Management in github.com/sap/cloud-security-client-go
CVE-2022-35293Critical· 9.1Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account
Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, an attacker can view or modify user data causing limited impact on confidentiality and in…