This page contains real SAP Security Notes sourced from SAP Patch Tuesday April 14, 2026. Timing recommendations are editorial — verify against official SAP Security Notes before acting on production systems.

April 2026 · 13 notes

Patch Intelligence

SAP Security Patches

Every SAP Security Note from Patch Tuesday, ranked by what actually matters to your landscape. Tier 1 products are in almost every SAP shop — missing a patch there is career-ending for BASIS admins.

1

Critical

2

High

8

Medium

2

Low

Severity
Timing

Tier 1 · Always covered

7 patches

Products in virtually every SAP environment. Patch these first, every month.

T12026-04-14
SAP BPC / SAP BW

SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse

A low-privileged authenticated user can upload a file containing arbitrary SQL statements that are then executed against the database. Full read, modify, and delete access to database content is possible. Manipulated planning figures, broken reports, and deleted consolidation data can result.

🔴Patch immediately
#3719353CVSS 9.9
T12026-04-14
SAP ERP / S/4HANA

Missing Authorization check in SAP ERP and SAP S/4HANA

An authenticated attacker can execute a specific ABAP program to overwrite any existing eight-character executable program without authorization. Impacts availability and integrity of the affected report. Confidentiality is not affected.

🟠Within 2 weeks
#3731908CVSS 7.1
T12026-04-14
SAP NetWeaver

Code Injection vulnerability in SAP NetWeaver AS Java (Web Dynpro)

Code injection vulnerability in the Web Dynpro Java runtime. An attacker could potentially inject and execute arbitrary code through the affected component.

🟡Next patch window
#3719397CVSS 6.1
T12026-04-14
SAP NetWeaver

Open Redirect vulnerability in SAP NetWeaver AS ABAP

An unauthenticated attacker can craft malicious URLs that, when accessed by a victim, redirect them to an attacker-controlled page. Affects confidentiality and integrity through potential phishing vectors.

🟡Next patch window
#3692004CVSS 6.1
T12026-04-14
SAP S/4HANA

Missing Authorization check in SAP Business Analytics and SAP Content Management

Remote-enabled function modules allow an authenticated user to access sensitive information beyond their intended permissions. After patching, the vulnerable function modules are no longer accessible remotely.

🟡Next patch window
#3705094CVSS 6.5
T12026-04-14
SAP HANA

Information Disclosure vulnerability in SAP HANA Cockpit and HANA Database Explorer

An information disclosure vulnerability in the HANA Cockpit and Database Explorer that could expose sensitive database configuration or data to unauthorized users.

🟡Next patch window
#3730639CVSS 5
T12026-04-14
SAP NetWeaver

CSS Injection vulnerability in SAP NetWeaver AS ABAP

A CSS injection vulnerability in SAP NetWeaver AS ABAP that could allow style injection attacks.

🟡Next patch window
#3665042CVSS 3.1

Tier 2 · Covered when notable

5 patches

Products with real deployments that have something worth acting on this month.

Previous months