H1 2026 showed a trend that has been developing for several years: business applications and ERPs are becoming increasingly attractive cyber targets.
ERP and other critical business applications hold some of an organization’s most valuable information and sit at the center of financial, HR, procurement, supply-chain, and other business processes. At the same time, cloud adoption, APIs, integrations, AI agents, and internet-facing components have made enterprise application environments more complex and difficult to defend.
Several events during the first six months of 2026 illustrate how this threat is evolving. Pathlock reviewed three defining H1 trends to identify key warning signs organizations should pay attention to during the second half of 2026 and beyond.
Warning Sign #1: Critical ERP Vulnerabilities Are a Continuous Security Problem
SAP opened 2026 by patching CVE-2026-0501, a CVSS 9.9 SQL injection vulnerability affecting SAP S/4HANA Financials / General Ledger. Moving forward, four of SAP’s six H1 monthly security releases contained at least one CVSS 9.9 vulnerability. This marks a worrying trend: for two consecutive half-years, SAP repeatedly disclosed near-maximum-severity vulnerabilities across core enterprise components. Five of six H2 2025 Patch Days also included at least one newly disclosed CVSS 9.9 or 10.0 vulnerability.
H2 2025 — Five of Six Patch Days Included a New CVSS 9.9/10.0 Vulnerability*
| Month | CVE | CVSS | Vulnerability / affected SAP product | SAP source |
|---|---|---|---|---|
| July 2025 | CVE-2025-42967 | 9.9 | Code Injection — SAP S/4HANA and SAP SCM (Characteristic Propagation) | SAP July 2025 Patch Day |
| August 2025 | CVE-2025-42957 | 9.9 | Code Injection — SAP S/4HANA Private Cloud and On-Premise | SAP August 2025 Patch Day |
| August 2025 | CVE-2025-42950 | 9.9 | Code Injection — SAP Landscape Transformation | SAP August 2025 Patch Day |
| September 2025 | CVE-2025-42944 | 10.0 | Insecure Deserialization — SAP NetWeaver AS Java | SAP September 2025 Patch Day |
| September 2025 | CVE-2025-42922 | 9.9 | Insecure File Operations — SAP NetWeaver AS Java (Deploy Web Service) | SAP September 2025 Patch Day |
| November 2025 | CVE-2025-42890 | 10.0 | Insecure Key and Secret Management — SAP SQL Anywhere Monitor | SAP November 2025 Patch Day |
| November 2025 | CVE-2025-42887 | 9.9 | Code Injection — SAP Solution Manager | SAP November 2025 Patch Day |
| December 2025 | CVE-2025-42880 | 9.9 | Code Injection — SAP Solution Manager | SAP December 2025 Patch Day |
H1 2026 — Four of Six Patch Days Included a New CVSS 9.9/10.0 Vulnerability*
| Month | CVE | CVSS | Vulnerability / affected SAP product | SAP source |
|---|---|---|---|---|
| January 2026 | CVE-2026-0501 | 9.9 | SQL Injection — SAP S/4HANA Private Cloud and On-Premise, Financials / General Ledger | SAP January 2026 Patch Day |
| February 2026 | CVE-2026-0488 | 9.9 | Code Injection — SAP CRM and SAP S/4HANA (Scripting Editor) | SAP February 2026 Patch Day |
| April 2026 | CVE-2026-27681 | 9.9 | SQL Injection — SAP Business Planning and Consolidation / SAP Business Warehouse | SAP April 2026 Patch Day |
| June 2026 | CVE-2026-44748 | 9.9 | XML Signature Wrapping — SAML Authentication in SAP NetWeaver AS ABAP / ABAP Platform | SAP June 2026 Patch Day |
* Methodology: Count only vulnerabilities newly disclosed in that month’s SAP Patch Day with a CVSS score of 9.9 or 10.0. Updates to previously disclosed CVEs are excluded.
The vulnerabilities appeared across the entire SAP ecosystem. In H2 2025, critical exposure included S/4HANA, SAP SCM, Landscape Transformation, NetWeaver AS Java, SAP Solution Manager and SQL Anywhere Monitor. In H1 2026, the affected technologies included S/4HANA Financials/General Ledger, CRM, Business Planning and Consolidation, Business Warehouse, and NetWeaver authentication.
The trend underscores the operational challenge facing organizations running large enterprise applications: vulnerabilities with potentially severe consequences can emerge repeatedly across different components of the environment.
Patching therefore cannot be treated as an occasional ERP maintenance exercise. Organizations need processes capable of continuously identifying exposure, prioritizing critical vulnerabilities, applying patches quickly, and implementing compensating controls where immediate remediation is impossible.
EXPERT COMMENTARY
“Four CVSS 9.9-or-higher vulnerabilities across six SAP patch cycles is a pattern, not a coincidence. SAP’s core financial and platform components carry decades of custom code, and every new API, AI agent, or cloud integration adds another way in. CISOs should expect this pace to hold through the second half of 2026 and into 2027. The real test is whether organizations can find and patch their own exposure faster than attackers can weaponize the next disclosure. Most can’t today, because they’re still tracking vulnerabilities in spreadsheets instead of continuously scanning their actual SAP landscape.”
— Chris Radkowski, Security and Risk Expert, Pathlock
Warning Sign #2: Business Applications Are Becoming Direct Targets
One of the clearest developments over the past year has been repeated attacker interest in Oracle’s business applications. The pattern emerged prominently in 2025 with Oracle E-Business Suite and continued into H1 2026 with both EBS and PeopleSoft.
- In October 2025, Oracle disclosed that CVE-2025-61882, a critical vulnerability in Oracle E-Business Suite, had been exploited in the wild. The flaw could be exploited remotely without authentication and potentially enable remote code execution. Google Threat Intelligence Group and Mandiant linked exploitation activity to the Cl0p extortion operation and found evidence suggesting attackers may have been exploiting Oracle EBS as early as August 9, 2025.
- In June 2026, Google Threat Intelligence Group and Mandiant observed ShinyHunters targeting Oracle PeopleSoft infrastructure between May 27 and June 9, 2026, including exploitation consistent with the previously undisclosed CVE-2026-35273. The campaign affected more than 100 organizations. The attackers used automated tooling to identify and target PeopleSoft environments. Oracle issued an out-of-band security alert on June 10, 2026.
- In late June 2026, public exploitation activity for CVE-2026-46817 was reported. The vulnerability had been patched by Oracle earlier in May. It affected the File Transmission component of Oracle EBS Payments and could be exploited remotely without authentication.
What the pattern tells us
That matters because ERP applications have historically been viewed as specialized, complex environments requiring significant expertise to attack. The PeopleSoft campaign in particular challenges any assumption that complexity provides meaningful protection: attackers demonstrated that discovery and exploitation of a specialized enterprise application could be automated and applied across many organizations.
The June attack on PeopleSoft was especially notable because once attackers broke in, they looked as legitimate users for an application, indicating the importance of having an application-layer monitoring and policy enforcement as an essential layer of ERP security and controls to alert defenders that something goes wrong.
EXPERT COMMENTARY
“The PeopleSoft campaign is the clearest signal yet that ERP attacks are industrializing. Attackers used automated tooling to find and hit more than 100 organizations in under two weeks, something that used to take specialized SAP or Oracle expertise applied one target at a time. Expect that same automation to reach more platforms over the next 6 to 12 months, because the economics favor it: one exploit, scaled across every internet-facing instance. What makes this hardest for defenders is that once attackers are in, they behave like ordinary users. Infrastructure and identity logs show a valid login. Only application-layer monitoring of the actual transactions, viewing records, changing configurations, moving data, will catch the difference.”
— Chris Radkowski, Security and Risk Expert, Pathlock
Warning Sign #3: Legitimate Application Access Is Becoming an Attack Path
A series of attacks involving Salesforce provides a warning for ERP security teams: attackers do not necessarily need to exploit a software vulnerability to reach sensitive business data. Existing permissions, stolen credentials, and trusted application connections can provide alternative routes in.
- On March 7, Salesforce disclosed a campaign targeting overly permissive guest-user configurations in publicly accessible Experience Cloud sites. Attackers were potentially able to access more organizational data than customers intended. Salesforce stressed that the issue was not an inherent vulnerability in its platform. Instead, the exposure resulted from how customers had configured access permissions. FINRA reported that ShinyHunters was mass-scanning public Experience Cloud sites and probing API endpoints to identify misconfigured guest profiles and access sensitive data.
- Between October 23 and November 19, 2025, attackers used compromised Gainsight tokens and connections to gain unauthorized access to Salesforce customer data. Again, Salesforce said the incident was not caused by a vulnerability in Salesforce itself, but by compromised connections between Gainsight and Salesforce.
- Then, in January 2026, Google/Mandiant identified an expansion of ShinyHunters-branded attacks targeting cloud SaaS applications. Attackers used vishing and credential-harvesting sites to steal SSO credentials and MFA codes before using that legitimate access to enter SaaS environments and steal sensitive information.
What It Means
Taken together, these incidents demonstrate that attackers do not necessarily need to exploit a vulnerability in the business application itself. Compromised trusted connections, stolen legitimate credentials, and excessive permissions can provide alternative routes to the same sensitive data and business processes in business applications and ERPs. As a result, securing application access increasingly means understanding not only whether an identity can authenticate, but what every human and non-human identity can access, whether those privileges remain appropriate, and what those identities actually do once inside critical applications.
EXPERT COMMENTARY
“The biggest application-access risk over the next year is something organizations already have on their hands: valid credentials and permissions being used the wrong way. Stolen logins, trusted third-party connections, and now AI agents acting on someone’s behalf all pass every authentication check attackers need, because access controls stop at the login screen. Security teams have to move past authentication and MFA as the finish line and start monitoring what identities, human and non-human, actually do once they’re inside financial, HR, and supply-chain systems. That means baselining normal business activity well enough to flag the moment it stops looking normal.”
— Chris Radkowski, Security and Risk Expert, Pathlock
Recommendations to Minimize ERP Risks in H2 2026
1. Prepare for ERP attacks to become more scalable
The PeopleSoft campaign demonstrated that even specialized enterprise applications can be identified and targeted across many organizations. Organizations should treat ERP systems as part of the external attack surface, continuously assess exposure, and ensure internet-facing components are minimized and hardened.
2. Protect the business action, not just the login
Strong authentication remains essential, but successful authentication does not mean that the activity is legitimate. Organizations need visibility into activity and transactions inside ERP applications—particularly changes to financial records, payments, privileges, master data, and other high-impact business processes—and controls capable of identifying activity that falls outside expected business context.
3. Continuously govern human and non-human access
Stolen credentials, excessive permissions, service accounts, APIs, integrations, and increasingly AI agents can all provide paths into sensitive business processes. Organizations should apply least privilege, regularly review access and trusted connections, and ensure both human and non-human identities have only the permissions required for their intended function.
4. Treat ERP patching as a continuous security discipline
SAP’s sustained run of near-maximum-severity vulnerabilities shows why ERP patching cannot be an occasional maintenance exercise. Organizations need repeatable processes to identify exposure, prioritize critical vulnerabilities, accelerate remediation, and deploy compensating controls where immediate patching is not possible.
5. Bring application-layer context into the SOC
Infrastructure and identity telemetry can show that an identity connected or authenticated, but may not explain the business significance of what happened next. SOC teams need application-level context that helps them understand who or what performed an action, what changed, which business process was affected, and whether the activity was appropriate.