SecurityBridge's research laboratory has identified CVE-2025-42957, a critical S/4HANA code injection vulnerability now confirmed as exploited in the wild. SAP has released an emergency patch. Icon's managed security clients were protected within hours of disclosure through automated SecurityBridge detection rules.
SecurityBridge Research Lab discovers critical SAP code injection vulnerability
Related news & insights
2026 SAP Trends: From Planning to Action on S/4HANA
For years, many organizations have acknowledged that moving to SAP S/4HANA is inevitable. Yet for many businesses, especially mid-market enterprises, the conversation has remained in the planning stage—evaluating options, building business cases, and waiting for the "right time."
SAP Q1 2026: Cloud backlog hits €21.9B, partner channel grows
SAP reported cloud revenue up 27% at constant currencies, with current cloud backlog reaching €21.9 billion. Indirect channel order entry grew significantly faster than direct, accounting for nearly 30% of quarterly volume — signalling sustained demand for partner-led delivery.
SAP Patch Day April 2026: what CISOs need to know
April's SAP Security Patch Day addresses multiple critical notes across S/4HANA and BTP. We break down which patches carry the highest risk, which affect APAC-common configurations, and what our SecurityBridge monitoring data shows about real-world exposure across our client base.