Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2951 articles · 110803 vulns · 36/41 feeds (7d)
← Back to list
2.0
CVE-2026-27675EXPLOITED
sap · sap landscape transformation

Code Injection vulnerability in SAP Landscape Transformation

Description

SAP Landscape Transformation contains a vulnerability in an RFC-exposed function module that could allow a high privileged adversary to inject arbitrary ABAP code and operating system commands. Due to this, some information could be modified, but the attacker does not have control over kind or degree. This leads to a low impact on integrity, while confidentiality and availability are not impacted.

Affected Products

VendorProductVersions
sapsap landscape transformationDMIS 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020, S4CORE 102, 103, 104, 105, 106, 107, 108, 109

References

  • https://me.sap.com/notes/3723097
  • https://url.sap/sapsecuritypatchday

Related News (1 articles)

Tier C
VulDB16h ago
CVE-2026-27675 | SAP Landscape Transformation up to S4CORE 102 code injection
→ No new info (linked only)
CVSS 3.12.0 LOW
VectorCVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-94
PublishedApr 14, 2026
Last enriched15h agov2
Trending Score38
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-27681EXP
SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse
Trending: 67
MEDIUMCVE-2026-27674EXP
Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java)
Trending: 44
MEDIUMCVE-2026-27683EXP
Reflected cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform
Trending: 40
HIGHCVE-2026-34256
Missing Authorization check in SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise)
Trending: 37
MEDIUMCVE-2026-24318
Insecure Session Management vulnerability in SAP BusinessObjects Business Intelligence Platform
Trending: 34

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 14, 2026
Discovered by ZDM
Apr 14, 2026
Updated: severity, activelyExploited
Apr 14, 2026
Actively Exploited
Apr 14, 2026

Version History

v2
Last enriched 15h ago
v2Tier C15h ago

Updated severity to CRITICAL and marked the vulnerability as actively exploited.

severityactivelyExploited
via VulDB
v121h ago

Initial creation