
For an intro, please read our former article from July, 2025.
Analyzing SAP security patches ("notes") between August 2018 and September 2026 reveals the following statistics, which are interesting.
In total, there are now 1,538 security notes which indicate the origin of the patched vulnerability, i.e. whether the underlying vulnerability was detected by SAP's internal procedures or by external parties. That’s an average of around 16 per month, representing a slight increase compared to our initial analysis. In this blog post we again only focus on the attributable patches. Based on this attribution, 394 (25.6%) security notes were detected by SAP, while 1,144 (74.4%) were detected by external parties. The contribution of external researchers increased by 1.3%.
The first insight is therefore that still the vast majority of SAP vulnerabilities are not discovered through SAP’s SDLC, but by independent experts who - usually - don’t even get paid for their efforts. In other words, more than 74% of SAP security notes address vulnerabilities that SAP’s security test teams did not discover, that SAP’s automated code security tools did not discover and that the contracted external testing companies did not discover.
This means that external / independent SAP security researchers make a substantial contribution to the security of the 480,000+ SAP customers across the globe.
However, focusing solely on the number of vulnerabilities could create an inaccurate picture. Theoretically the vulnerabilities reported by external parties might be of low risk and therefore not be addressed internally by SAP’s security procedures.
Taking criticality into account - based on the CVSS rating associated with the security notes - we can see that 130 out of 184 security notes with a CVSS score of 9.0 or higher were reported by external researchers. That’s about 70.7% (an increase of 3 percent), meaning that the value of external research to SAP customers is increasingly noteworthy in the more critical area.
Taking it one step further, we only consider security notes with a CVSS score of 10.0, i.e. extremely dangerous vulnerabilities that could most likely destroy an SAP system. In this case we see that 16 out of 36 security notes are based on external research. That’s "only" around 44.4%, but still an increase of more than 5 percent compared to last year!
While SAP is still the leader in the high end vulnerabilities, it seems the researchers are catching up quickly.
What eight years of SAP Security Notes tell you about steering the patch process.
272 notes (18.5 % of those with a scorable vector) are reachable over the network and exploitable without authentication and without user interaction — CVSS vector AV:N / PR:N / UI:N. This group is measurably more severe than the rest: mean CVSS 7.43 against 6.04.
For planning, though, what counts is not its severity but its steadiness. While total volume swings between 147 and 217 notes a year, this group has stayed in a band of 32 to 40 since 2020.
Consequence
Emergency capacity can be planned against a fixed figure of roughly three cases a month.
Of the 103 notes scoring CVSS 9.8 or above, 32 do not trace back to SAP’s own code but to bundled third-party libraries, mainly Log4Shell (CVE-2021-44228) and Spring4Shell (CVE-2022-22965).
Consequence
A substantial part of SAP risk is supply-chain risk. However, SAP patches for products using vulnerable libraries come with an inherent delay.
52% of all vulnerabilities are caused by Missing Authorization, Cross-Site Scripting and Information Disclosure, only 4% of them being critical.
11% of all vulnerabilities are caused by Code Injection, Remote Code Execution (RCE) and Missing Authentication, with 52% of them being critical.
Consequence
Risk-based prioritization enables faster reduction of critical exposure.
Out of 312 affected software components, 41% are only mentioned in one security note while 8.3% are mentioned in 15 or more security notes.
Most vulnerabilities were found in SAP_BASIS, S4CORE, ENTERPRISE (Business Objects) and KERNEL.
Consequence
Repeated patching of core components creates a recurring trade-off between reducing cyber risk and maintaining business availability.
If you are a CISO in the D-A-CH area you are invited to join the next SAP Cyber Defense Round Table event.