CVE-2026-27681Patch

MEDIUMCVSS 9.9 · CRITICAL

Exploitation observed; activity peaked at 11 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the confidentiality, integrity, and availability of the system.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 18 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 16 signals
  • Disclosure: 6 classified signals
  • General: 4 classified signals
  • Peaked 4d ago at 11 mentions (2026-04-14); latest day: 1
  • 18 total mentions across 5 days

Deep dive

Activity timeline18 mentions / 5d
036811Mentions · 2026-04-14: 11Mentions · 2026-04-15: 2Mentions · 2026-04-16: 1Mentions · 2026-04-17: 3Mentions · 2026-04-21: 1PoC Mentioned / Linked · 2026-04-14: 1Active Exploitation · 2026-04-15: 1Patch / Workaround · 2026-04-14: 5Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-14: 10Technical Details · 2026-04-15: 2Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 2Technical Details · 2026-04-21: 104-1404-1504-1604-1704-21
Signal classification4 categories
Patch
738.9%
Disclosure
633.3%
General
422.2%
Active Exploitation
15.6%
Referenced assets19 URLs
Classification over time
DateTotalLabels
2026-04-1411
Disclosure4General2Patch5
2026-04-152
Active Exploitation1Disclosure1
2026-04-161
Patch1
2026-04-173
Disclosure1General2
2026-04-211
Patch1
Full discourse18 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🏢 أنظمة Enterprise: ⚙️ نظام Cisco ISE: التقييم: 9.9 | (CVE-2026-20147, 20180, 20186) ⚠️ تسمح للمستخدم الإداري بتنفيذ أوامر عن بُعد (RCE) وترقية الصلاحيات إلى Root. 📊 نظام SAP Business Planning: التقييم: 9.9 | (CVE-2026-27681) ⚠️ هجوم (SQL Injection) في ABAP يتيح التحكم بقواعد البيانات . 🔑 نظام Cisco Webex SSO: التقييم: 9.8 | (CVE-2026-20184) ⚠️ تخطي المصادقة الموحدة.

    Post summary

    The post announces several high‑score CVEs affecting Cisco and SAP Enterprise systems, detailing the nature of the vulnerabilities (RCE, SQL injection, auth bypass) but offering no PoC, exploit tools, active exploitation evidence, or patch information.

    100421.8K
    49.3K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Disclosure

    🚨 Upozorňujeme na kritickou zranitelnost v SAP Business Planning and Consolidation (BPC) a SAP Business Warehouse (BW), CVE-2026-27681. Zranitelnost typu SQL Injection s hodnocením CVSS 9.9 umožňuje neautentizovanému nebo nízko privilegovanému útočníkovi vkládat škodlivé SQL dotazy do aplikačních vstupů, což může vést k úplnému kompromitování databáze, úniku nebo manipulaci s citlivými daty a potenciálně i k převzetí kontroly nad dotčeným SAP systémem. Zneužití je možné v prostředích používajících zranitelné verze HANABPC 810, BPC4HANA 300 a SAP_BW 750-758 a 816, a to zejména v případě, že jsou vystaveny síťově dostupným rozhraním bez dodatečných ochranných mechanismů. Úspěšný útok může mít zásadní dopad na integritu, důvěrnost i dostupnost podnikových dat a provozních procesů. 📌Doporučujeme aktualizovat na nejnovější verzi.

    Post summary

    The post announces a critical SQL Injection flaw (CVE-2026-27681) in SAP BPC and BW, provides technical details, and urges users to apply the latest patch.

    020501.2K
    4.2K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Patch

    ぱっちちゅーずでー ◆ Microsoft 2026 年 4 月のセキュリティ更新プログラム (月例) https://www.microsoft.com/en-us/msrc/blog/2026/04/202604-security-update CVE-2026-33825 Microsoft Defender の特権の昇格の脆弱性 CVE-2026-32201 Microsoft SharePoint Server のなりすましの脆弱性 ◆Fortinet https://fortiguard.fortinet.com/psirt ・FG-IR-26-100 / CVE-2026-39808 FortiSandbox 4.4系のAPIにある OSコマンドインジェクション。細工したリクエストを受けると、認証なしで任意コードや任意コマンドを実行される恐れがあります。外部公開や到達可能性がある環境では、優先度高めでの確認が必要です。 ・FG-IR-26-112 / CVE-2026-39813 FortiSandbox のJRPC APIにある パストラバーサル起因の認証回避・権限昇格。特別に細工したHTTPリクエストで未認証のまま認証をバイパスし、権限を引き上げられる可能性があるため、管理API露出環境では特に注意が必要です。 ・FG-IR-26-121 / CVE-2026-22828 FortiAnalyzer Cloud / FortiManager Cloud の oftpd にある ヒープベースのバッファオーバーフロー。細工したリクエストにより、リモートの未認証攻撃者が任意コードやコマンド実行に至る可能性がありますが、悪用にはASLRや分離構成を踏まえた準備が必要です。 ◆Ivanti https://www.ivanti.com/blog/april-2026-security-update https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-4913-CVE-2026-4… ◆Adobe(Criticalで任意のコード実行のみ抽出) https://helpx.adobe.com/security.html ・Adobe ColdFusion(APSB26-38) CVE-2026-27304, CVE-2026-27306 入力検証不備により、任意のコード実行につながる脆弱性 ・Adobe Connect(APSB26-37) CVE: CVE-2026-27302, CVE-2026-27303, CVE-2026-27243, CVE-2026-27245, CVE-2026-27246, CVE-2026-34615 デシリアライズ不備や XSS を起点に、任意のコード実行が可能となる脆弱性 ・Adobe FrameMaker(APSB26-36) CVE: CVE-2026-27290, CVE-2026-27292, CVE-2026-27293, CVE-2026-27294, CVE-2026-27295, CVE-2026-27296, CVE-2026-27297, CVE-2026-27298 任意のコード実行につながる脆弱性群 ・Adobe Bridge(APSB26-39) CVE: CVE-2026-34630, CVE-2026-27310, CVE-2026-27311, CVE-2026-27312, CVE-2026-27313 複数のヒープベース・バッファオーバーフローにより、任意のコード実行が可能になる脆弱性 ・Adobe Photoshop(APSB26-40) CVE: CVE-2026-27289 境界外読み取りにより、任意のコード実行につながる脆弱性 ・Adobe Illustrator(APSB26-42) CVE: CVE-2026-34618 境界外書き込みにより、任意のコード実行につながる脆弱性 ◆SAP SAP Security Patch Day - April 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/april-2026.html CVE-2026-27681 https://www.cve.org/CVERecord?id=CVE-2026-27681 『(直訳)SAP Business Planning and ConsolidationおよびSAP Business Warehouseにおける認証チェックの不備により、認証済みのユーザーが細工されたSQL文を実行してデータベースデータを読み取り、変更、削除できる脆弱性が存在します。これは、システムの機密性、完全性、可用性に重大な影響を及ぼします。』

    Post summary

    The message showcases a consolidated vendor security update, listing numerous CVEs across major platforms and emphasizing the availability of patches and remediation guidance.

    000321.4K
    11.7K followersView on X
  • Cert-IST@cert_ist
    Patch

    SAP a annoncé 20 publications et mises à jour de notes de sécurité dans son "Security Patch Day" d'Avril 2026. Parmi les vulnérabilités corrigées, CVE-2026-27681 (score CVSS de 9.9), un bug d'injection SQL pouvant mener à une exécution de code arbitraire. https://tinyurl.com/33wb2meu

    Post summary

    SAP’s April 2026 Security Patch Day includes 20 updates, notably patching CVE-2026-27681, an SQL injection flaw that could enable arbitrary code execution.

    0101082
    961 followersView on X
  • iototsecnews@iototsecnews
    Patch

    SAP の 2026/04 Patch Day:深刻な SQLi の脆弱性 CVE-2026-27681 などを FIX https://iototsecnews.jp/2026/04/14/sap-patch-day-fixes-critical-sql-injection-dos-and-code-injection-flaws/ 2026年4月の Security Patch Day において修正された複数の脆弱性は、データベース操作やユーザー権限の確認といった、基盤となる処理の不備に起因するものです。最も深刻な SQL インジェクションの脆弱性 CVE-2026-27681 (CVSS 9.9) は、SAP Business Warehouse などにおける入力データの不十分な検証に起因し、データベースへ向けた不正な命令の送信を許すものです。ご利用のチームは、ご注意ください。 #CVE202627681 #PatchTuesday #SAP #Vulnerability

    Post summary

    The post announces that SAP’s 2026/04 Patch Day addressed the critical SQL injection vulnerability CVE‑2026‑27681, providing a CVSS score and a brief technical explanation, but it does not mention any PoC, exploit tool, or active exploitation.

    01000113
    486 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos SAP ❗ CVE-2026-34256 ❗ CVE-2026-27681 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-sap-7/ https://t.co/NZyGfTNrVP

    Post summary

    The post announces two SAP product CVEs and directs readers to external links, but provides no additional technical details, exploitation evidence, or mitigation information.

    00010113
    6.7K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    April Patch Tuesday fixes critical flaws in SAP BPC/BW SQL injection (CVE-2026-27681, CVSS 9.9), Adobe Acrobat Reader RCE, Fortinet FortiSandbox, and Microsoft SharePoint Server. #SAPSecurity #AdobeFixes #USA https://ift.tt/VftKvAp

    Post summary

    Patch Tuesday addressed several critical vulnerabilities, notably a high‑CVSS SQL injection in SAP BPC/BW (CVE‑2026‑27681), along with RCE in Adobe Acrobat Reader, and issues in Fortinet FortiSandbox and Microsoft SharePoint Server.

    00010226
    4.0K followersView on X
  • CCB Alert@CCBalert
    Patch

    SAP released its monthly Security Patch Day updates, addressing multiple severe vulnerabilities, including CVE-2026-27681, that allows an authenticated attacker with low privileges and without user interaction to execute arbitrary SQL commands over the network. Patch Patch Patch

    Post summary

    SAP's Security Patch Day released a fix for CVE-2026-27681, a low‑privilege SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL over the network.

    00010224
    7.2K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    SAP released 20 security notes in April 2026, including critical CVE-2026-27681 SQL injection in Business Planning & Consolidation and BW, plus high-severity CVE-2026-34256 in ERP & S/4 HANA. #SAPSecurity #ABAPPatch #Germany https://ift.tt/wD98s7E

    Post summary

    SAP released 20 security notes in April 2026, detailing critical CVE‑2026‑27681 (SQL injection) and high‑severity CVE‑2026‑34256, along with the corresponding patches.

    00010255
    4.0K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-27681 — CVSS 9.9/10 ██████████ Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/TSw9FAUoOe

    Post summary

    The tweet announces CVE-2026-27681, a critical SAP vulnerability with a CVSS of 9.9, and urges a patch, but offers limited technical detail and no evidence of active exploitation.

    1000036
    23 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    General

    🔒 #CyberSecurity CVE-2026-27681: Critical SAP SQL Injection — Detection and Hardening Guide "April's Patch Tuesday releases a critical wake-up call for organizations relying on SAP…" 🔗 https://securityarsenal.com/blog/cve-2026-27681-critical-sap-sql-injection-detection-and-hardening-guide #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesday

    Post summary

    A blog post announces CVE-2026-27681 as a critical SAP SQL injection and offers a detection and hardening guide, but does not provide PoC, exploit code, patch details, or evidence of active exploitation.

    0000064
    10 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-27681 can escalate privileges in SAP environments and move laterally across networks via database compromise. Runtime segmentation helps contain post-compromise activity by limiting blast radius across critical business systems. #CloudSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/april-2026-patch-tuesday-critical-vulnerabilities

    Post summary

    CVE-2026-27681 is actively exploited to gain privileged access in SAP environments and facilitate lateral movement via database compromise, with runtime segmentation suggested as a mitigation.

    0000041
    1.9K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-27681 📊 Severity: 9.9 🚨 Risk Level: Critical 🧩 Affects: Sap Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-27681 #CVE-2026-27681 #CVE #Critical #Sap #CyberSecurity #InfoSec https://t.co/11xGw8zcE6

    Post summary

    A new high‑severity CVE (CVE‑2026‑27681) affecting SAP is announced, with basic details such as score and risk level but no PoC, exploit, or remediation mentioned.

    0000033
    137 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27681 SQL Injection in SAP Business Planning and Consolidation and Business Warehouse https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27681

    Post summary

    The text announces CVE‑2026‑27681 as a SQL injection vulnerability affecting SAP Business Planning, Consolidation and Business Warehouse, referencing a vulnerability details page but providing no exploit, patch, or mitigation details.

    0000047
    4.0K followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-27681 | CVSS 9.9 🔴 CVE-2026-6195 | CVSS 9.8 🔴 CVE-2026-22563 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post lists three high‑severity CVEs with their CVSS scores and a link to a site for more information, but provides no details on exploitation, patches, or technical specifics.

    0000067
    5.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27681 Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statemen… https://www.cve.org/CVERecord?id=CVE-2026-27681

    Post summary

    The CVE‑2026‑27681 report indicates an authorization flaw in SAP Business Planning and Consolidation and SAP Business Warehouse that allows an authenticated user to execute crafted SQL statements, but no PoC, exploit, patch, or active exploitation is mentioned.

    0000086
    57.2K followersView on X
  • CVEFind.com@CveFindCom
    General

    [CVE-2026-27681: CRITICAL] Insufficient authorization checks in SAP BPC & BW allow users to execute SQL statements, jeopardizing data confidentiality, integrity, and system availability.#cve,CVE-2026-27681,#cybersecurity https://cvefind.com/CVE-2026-27681

    Post summary

    The post highlights a critical SAP BPC & BW authorization flaw that enables arbitrary SQL execution but provides no evidence of exploitation, PoC, or remediation.

    0000047
    620 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-27681: SQL ... SAP's auth bypass letting low-privs dump entire BW/BPC databases with crafted SQL - 9.9 CVSS means your financial data is toast #SQLi #SAPsec #BPC. https://zerodaysignal.com/vulnerability/CVE-2026-27681 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-27681, revealing an authentication bypass in SAP BW/BPC that lets low‑privilege users dump databases via crafted SQL, rated CVSS 9.9; no patch, exploit code, or active exploitation is reported.

    00000106
    218 followersView on X

Explore more