إبراهيم بوحيمد | Ibrahim Buhaimed[verified]@buhaimediDisclosure
The post announces several high‑score CVEs affecting Cisco and SAP Enterprise systems, detailing the nature of the vulnerabilities (RCE, SQL injection, auth bypass) but offering no PoC, exploit tools, active exploitation evidence, or patch information.
GovCERT.CZ[verified]@GOVCERT_CZDisclosure
The post announces a critical SQL Injection flaw (CVE-2026-27681) in SAP BPC and BW, provides technical details, and urges users to apply the latest patch.
にゃん☆たく/takumi.a[verified]@taku888infinityPatch
The message showcases a consolidated vendor security update, listing numerous CVEs across major platforms and emphasizing the availability of patches and remediation guidance.
Orizon[verified]@OrizonCyberPatch
The tweet announces CVE-2026-27681, a critical SAP vulnerability with a CVSS of 9.9, and urges a patch, but offers limited technical detail and no evidence of active exploitation.
Security Arsenal, LLC[verified]@SecurityAr58409General
A blog post announces CVE-2026-27681 as a critical SAP SQL injection and offers a detection and hardening guide, but does not provide PoC, exploit code, patch details, or evidence of active exploitation.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
CVE-2026-27681 is actively exploited to gain privileged access in SAP environments and facilitate lateral movement via database compromise, with runtime segmentation suggested as a mitigation.
Cert-IST@cert_istPatch
SAP’s April 2026 Security Patch Day includes 20 updates, notably patching CVE-2026-27681, an SQL injection flaw that could enable arbitrary code execution.
iototsecnews@iototsecnewsPatch
The post announces that SAP’s 2026/04 Patch Day addressed the critical SQL injection vulnerability CVE‑2026‑27681, providing a CVSS score and a brief technical explanation, but it does not mention any PoC, exploit tool, or active exploitation.