
4/6: Beyond the Criticals It's not just the 9.6 flaws. We're seeing: 🔥 CVE-2026-34259 (CVSS 8.2): OS Command Injection in SAP Forecasting & Replenishment. 🔥 CVE-2026-40135 (CVSS 6.5): Similar injection flaw in NetWeaver AS ABAP. Attackers are increasingly targeting these "sidecar" applications to gain a foothold in the network.
Post summary
The post discloses two new SAP component vulnerabilities (OS Command Injection) with CVSS scores, warning that attackers are increasingly targeting these sidecar applications for network footholds.

