Find notable cyber news and cases, enriched with sources, timelines, and signals.

SAP security patch release for CVE-2019-17571

Security Patch Release
First reported
Last updated
Happening score
H score 42
1 unique sources, 1 articles

Summary

Hide ▲

SAP released security updates for two critical flaws in FS-QUO and NetWeaver Enterprise Portal Administration, reducing the risk of arbitrary code execution on affected systems. The patched issues are CVE-2019-17571 and CVE-2026-27685, rated 9.8 and 9.1 respectively. One flaw is a code injection issue tied to an outdated Apache Log4j 1.2.17 artifact, while the other is an insecure deserialization weakness in uploaded content handling. Both bugs were severe enough to warrant immediate vendor fixes for affected SAP deployments.

Related Happenings

SAP NetWeaver Application Server ABAP SICF workaround for CVE-2026-44747

Advisory/Mitigation
H score40 First: 14.07.2026 21:17 Last: 14.07.2026 21:17 Sources 1

About this happening: SAP NetWeaver Application Server ABAP customers now have a temporary workaround for CVE-2026-44747 that can reduce exposure to memory corruption. The mitigation disabl...

SAP security patch release for CVE-2026-44747

Security Patch Release
H score40 First: 14.07.2026 21:17 Last: 14.07.2026 21:17 Sources 1

About this happening: SAP's July 2026 security updates now cover multiple vulnerabilities, including a critical SAP NetWeaver Application Server ABAP flaw. The bundle includes CVE-2026-44...

SAP July 2026 security updates

Security Patch Release
H score31 First: 14.07.2026 14:42 Last: 14.07.2026 14:42 Sources 1

About this happening: SAP's July 2026 security updates address 16 vulnerabilities across NetWeaver, Commerce Cloud, and AppRouter, including three critical flaws. The release closes a *...

SAP July 2026 security patch day

Security Patch Release
H score40 First: 14.07.2026 14:17 Last: 14.07.2026 14:17 Sources 1

About this happening: SAP released 19 new and updated security notes for its July 2026 security patch day, covering NetWeaver, Approuter, Commerce Cloud, and other products with...

Splunk Enterprise security update for CVE-2026-20253

Security Patch Release
H score52 First: 13.06.2026 16:23 Last: 13.06.2026 16:23 Sources 1

About this happening: Splunk released security updates for CVE-2026-20253, fixing a critical Splunk Enterprise flaw that could enable unauthenticated file operations and remote code e...

Timeline

  1. 11.03.2026 14:26 2 articles · 4mo ago

    SAP releases security updates for two critical flaws

    Initial Disclosure

    SAP released security updates for SAP Quotation Management Insurance application (FS-QUO) and SAP NetWeaver Enterprise Portal Administration to address CVE-2019-17571 and CVE-2026-27685, two critical vulnerabilities that could enable arbitrary code execution on affected systems. One flaw is a code injection issue tied to an outdated Apache Log4j 1.2.17 artifact with CVSS 9.8, and the other is an insecure deserialization weakness involving uploaded content with CVSS 9.1.

    Show sources