Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-76963 — Missing Authorization Check in Application Server ABAP of SAP NetWeaver and ABAP Platform

Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration informat…

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
4.3 MEDIUM
CVE-2026-76962 — Missing Authorization check in SAP S/4HANA (Manage Bank Chains app)

SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to d…

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
3.5 LOW
CVE-2026-76961 — Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Paym…

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a mali…

Remote | Cross-Site Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
3.5 LOW
CVE-2026-76960 — Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Paym…

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a mali…

Remote | Cross-Site Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
4.6 MEDIUM
CVE-2026-76959 — Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Paym…

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malic…

Remote | Cross-Site Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.5 HIGH
CVE-2026-76958 — XML External Entity (XXE) Vulnerability in SAP Integration Suite

SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML p…

Remote | XML External Entity
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.0 CRITICAL
CVE-2026-66768 — Improper Access Control in SAP NetWeaver (SAP GUI for Java)

SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating…

netweaver | Remote | Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.7 HIGH
CVE-2026-66767 — Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Pla…

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potenti…

netweaver_application_server_abap | Remote | Race Condition
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.8 CRITICAL
CVE-2026-58240 — Missing Authentication check in SAP NetWeaver (Message Server)

SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affe…

netweaver | Remote | Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
2.2 LOW
CVE-2026-58234 — Denial of Service vulnerability in SAP Process Integration (SOAP Adapter)

SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increa…

process_integration | Remote | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-44766 — SQL Injection vulnerability in SAP S/4HANA (Intercompany Matching and Reconciliation)

SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without prop…

Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
10.0 CRITICAL
CVE-2026-44756 — Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request contain…

Remote | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.1 HIGH
CVE-2026-86544 — knowns before 0.30.0 Authorization Bypass via Misclassified Code Actions

knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
9.8 CRITICAL
CVE-2026-86543 — knowns before 0.30.0 Unauthenticated Management API Exposure

knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthen…

Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
9.1 CRITICAL
CVE-2026-86542 — knowns before 0.30.0 Path Traversal via Import Name

knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in …

Remote | Path Traversal
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.3 HIGH
CVE-2026-86541 — knowns before 0.30.0 Path Traversal via code.replace MCP action

knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can sup…

Remote | Path Traversal
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.5 HIGH
CVE-2026-86540 — knowns before 0.30.0 Arbitrary Code Execution via LSP Binary

knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns…

| Misconfiguration
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.2 HIGH
CVE-2026-86539 — knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint

knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without valida…

Remote | Server-Side Request Forgery
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.7 HIGH
CVE-2026-86538 — knowns before 0.30.0 Path Traversal via templateFile parameter

knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply di…

Remote | Path Traversal
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.8 HIGH
CVE-2026-86439 — knowns before 0.30.0 Path Traversal via MCP doc and memory tools

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supp…

Remote | Path Traversal
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
Showing 20 of 12534 Results