Zero-Day Protection for SAP

When a zero-day vulnerability is detected, the clock starts ticking immediately. There’s no patch available yet, so how do you protect your enterprise? Even when SAP releases a Security Note to patch a zero-day flaw, advanced threat actors can reverse-engineer security notes and launch active exploits in under 72 hours. Meanwhile, patching critical SAP systems require significant planning to schedule downtime, leaving production systems exposed for weeks or even months and defenders at a distinct disadvantage.
On one hand, your hands may be tied and emergency patching with downtime may not be immediately possible. On the other hand, you can’t afford to leave them unprotected either.
The Onapsis Research Labs have you covered. Our deep vulnerability research paired with the telemetry from our Global Threat Intelligence Network has armed Onapsis with threat insights that can be immediately productized for our clients. In 2025 alone, the Onapsis Research Labs were responsible for the discovery of roughly 55% of all SAP HotNews vulnerabilities (i.e., CVSS 9.0-10.0), and we’re on a similar pace in 2026. This level of output means that Onapsis has the knowledge on how to shield your live SAP environments before official SAP Security Notes are even released. On average, Onapsis delivers zero-day pre-patch protection to our customers 120 days before patches are available!
Why Traditional Security Fails Against Zero-Day SAP Attacks
Conventional firewalls, endpoint EDR, and generic vulnerability scanners are all useful components of a defense-in-depth enterprise security strategy. However, their capabilities all stop at the SAP perimeter. To them, your SAP applications are unreadable black boxes.
When a zero-day vulnerability emerges in a core SAP application, generic security tools leave organizations exposed. SAP is extraordinarily complex and a closed ecosystem. Securing business-critical applications such as SAP requires deep knowledge that non-specialist security vendors lack. Criminal chatter regarding SAP zero-days has grown by 490%, accompanied by a 400% surge in targeted ransomware campaigns designed specifically to encrypt ERP data. Further, threat actors leveraging AI tooling can accelerate exploit creation dramatically and significantly increase risk for enterprises until an SAP Security Note is made available.


Battle-Tested in Global Threat Campaigns
When zero-day SAP campaigns hit enterprise software, Onapsis provides immediate threat visibility and verified remediation within hours rather than weeks.
During major global zero-day events (such as the widespread exploitation of SAP NetWeaver Visual Composer components CVE-2025-31324 and CVE-2025-42999), Onapsis Research Labs led the global response:
- Earliest Reconnaissance Detection: Onapsis sensors captured real-world exploit payloads weeks before public disclosure, allowing the Onapsis Research Labs to reconstruct the full remote code execution (RCE) attack path.
- Root-Cause Patch Collaboration: Onapsis shared forensic analysis directly with the SAP Product Security Response Team, enabling the vendor to issue a revised patch addressing the underlying deserialization flaw.
- Rapid Virtual Shielding: Onapsis customers received both immediate and continuous threat rule updates via Onapsis Defend, maintaining complete system protection while official vendor notes were authored and updated during a rapidly evolving zero-day campaign.
The Proven Authority in Zero-Day SAP Research
Our research team brings over 85 combined years of specialized cybersecurity experience, maintaining direct lockstep collaboration with global emergency response agencies and software vendors.
Onapsis researchers have discovered and responsibly disclosed over 1,000 zero-day vulnerabilities in enterprise applications.
In 2025 alone, Onapsis discovered 55% of all critical, CVSS 9.0+ HotNews vulnerabilities in SAP software.
Federal cybersecurity agencies rely directly on Onapsis insights and telemetry to brief government officials, assist in publishing national threat advisories, and inform inclusion in CISA’s Known Exploited Vulnerabilities (KEV) catalog.
Our proprietary intelligence engine indexes over 10,000 application-layer vulnerabilities, attack behaviors, and threat actor tactics, techniques, and procedures (TTPs).
Our continuous collaboration is formally recognized in the official SAP Security Researcher Acknowledgements, confirming our status as the leading, most prolific independent threat research contributor to SAP.
What’s Needed to Defend SAP in the New AI Era?
Frontier AI models (like Mythos) are powering a surge in new vulnerability discovery, leading to thousands of new vulnerabilities. SAP, like all other software vendors, will face a larger backlog, leading to potential delays in patch delivery as well as more frequent, higher volume patch releases. Your enterprise exposure cycle will lengthen significantly, as the lag between discovery and patch availability will continue to worsen.
Meanwhile, state-sponsored and ransomware threat actors are rapidly operationalizing off-the-shelf AI to exploit SAP systems. Groups involved with the SAP zero-day in 2025 are already proficient AI users. Unfortunately, not every SAP system can be patched in a timely manner, and not every flaw will have a Security Note available in a timely manner. As time-to-exploit drops closer to zero, the enterprise needs to move significantly faster than they ever have before, and this is where the need to move at “machine speed” is derived.
Ultimately, to be successful in this AI era, enterprises must
- Utilize continuous, high-fidelity SAP threat intelligence to monitor active threat actors and targets;
- Leverage multi-checkpoint code security to protect against AI-generated custom SAP code vulnerabilities;
- Deploy pre-patch SAP protection and compensating controls;
- Implement agentic AI workflows to achieve more efficient exposure management and machine-speed defense against active SAP threats.
Without continuous, high-fidelity threat intelligence, all the rest of these requirements fail. This is where Onapsis and our Onapsis Research Labs fill the gap for the world’s largest enterprises in securing their mission-critical SAP landscapes as the key foundation for agentic SAP security orchestration.

Eliminate Your SAP Cybersecurity Blind Spot
Protect your business-critical applications from unpatched vulnerabilities, machine-speed attacks, and active zero-day campaigns.

