← Back to BrewedIntel
vulnerabilitycriticalMultiple Critical VulnerabilitiesRemote Code ExecutionSQL InjectionCVE-2026-27681

Apr 15, 2026 • [email protected] (The Hacker News)

April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More

April Patch Tuesday addresses critical vulnerabilities across multiple enterprise vendors including SAP, Adobe, Microsoft, and Fortinet. The most severe is an...

Source
The Hacker News
Category
vulnerability
Severity
critical

Executive Summary

April Patch Tuesday addresses critical vulnerabilities across multiple enterprise vendors including SAP, Adobe, Microsoft, and Fortinet. The most severe is an SQL injection flaw (CVE-2026-27681, CVSS 9.9) in SAP Business Planning and Consolidation and SAP Business Warehouse, potentially allowing arbitrary database execution. Organizations using affected SAP, Adobe, Fortinet, and Microsoft products should prioritize immediate patching to mitigate risk of exploitation. The high CVSS scores across multiple vulnerabilities indicate significant potential for enterprise impact if left unpatched.

Summary

A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April's Patch Tuesday releases. Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS score: 9.9) that could result in the execution of arbitrary database

Published Analysis

April Patch Tuesday addresses critical vulnerabilities across multiple enterprise vendors including SAP, Adobe, Microsoft, and Fortinet. The most severe is an SQL injection flaw (CVE-2026-27681, CVSS 9.9) in SAP Business Planning and Consolidation and SAP Business Warehouse, potentially allowing arbitrary database execution. Organizations using affected SAP, Adobe, Fortinet, and Microsoft products should prioritize immediate patching to mitigate risk of exploitation. The high CVSS scores across multiple vulnerabilities indicate significant potential for enterprise impact if left unpatched. A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April's Patch Tuesday releases. Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS score: 9.9) that could result in the execution of arbitrary database A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April's Patch Tuesday releases. Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS score: 9.9) that could result in the execution of arbitrary database

Linked Entities

  • CVE-2026-27681