SAP Security Patch Day decoded V2: Who’s really keeping your ERP secure?

September 12, 2026

Category:

Zero Days and Patches

Read time:

2

For an intro, please read our former article from July, 2025.

Our current analysis of the origin of SAP security patches ("notes") yields the following numbers and insights:

Analyzing data between August 2018 and September 2026 reveals the following statistics, which are interesting.

In total, there are now 1538 Security notes which indicate the origin of the patched vulnerability, i.e. whether the underlying vulnerability was detected by SAP's internal procedures or by external parties. That’s an average of around 16 per month, a slight increase to the initial analysis. In this blog post we again only focus on the attributable patches. Based on this attribution, 394 security notes were detected by SAP (25,6%), while 1144 (74,4%) were detected by external parties. The contribution of external researchers increased by 1,3%.

The first insight is therefore that still the vast majority of SAP vulnerabilities are not discovered through SAP’s SDLC, but by independent experts who - usually - don’t even get paid for their efforts. In other words, more than 74% of SAP security notes address vulnerabilities that SAP’s security test teams did not discover, that SAP’s automated code security tools did not discover and that the contracted external testing companies did not discover.

This means that external / independent SAP security researchers provide a substantial contribution to the security of the 480.000+ SAP customers across the globe.

However, focusing solely on the number of vulnerabilities could create an inaccurate picture. Theoretically the vulnerabilities reported by external parties might be of low risk and therefore not be addressed internally by SAP’s security procedures.

Taking criticality into account - based on the CVSS rating associated with the security notes - we can see that 130 out of 184 security notes with a CVSS score of 9.0 or higher were reported by external researchers. That’s about 70.7% (an increase of 3 percent), meaning that the value of external research to SAP customers is increasingly noteworthy in the more critical area.

Taking it one step further, we only consider security notes with a CVSS score of 10.0, i.e. extremely dangerous vulnerabilities that could most likely destroy an SAP system. In this case we see that 16 out of 36 security notes are based on external research. That’s "only" around 44,4%, but still an increase of more than 5 percent compared to last year!

While SAP is still the leader in the high end vulnerabilities, it seems the researchers are catching up quickly. Who’s really keeping your ERP secure?