Zero-Day Protection for SAP

When a zero-day vulnerability is detected, the clock starts ticking immediately. There’s no patch available yet, so how do you protect your enterprise? Even when SAP releases a Security Note to patch a zero-day flaw, advanced threat actors can reverse-engineer security notes and launch active exploits in under 72 hours. Meanwhile, patching critical SAP systems require significant planning to schedule downtime, leaving production systems exposed for weeks or even months and defenders at a distinct disadvantage.

On one hand, your hands may be tied and emergency patching with downtime may not be immediately possible. On the other hand, you can’t afford to leave them unprotected either.

The Onapsis Research Labs have you covered. Our deep vulnerability research paired with the telemetry from our Global Threat Intelligence Network has armed Onapsis with threat insights that can be immediately productized for our clients. In 2025 alone, the Onapsis Research Labs were responsible for the discovery of roughly 55% of all SAP HotNews vulnerabilities (i.e., CVSS 9.0-10.0), and we’re on a similar pace in 2026. This level of output means that Onapsis has the knowledge on how to shield your live SAP environments before official SAP Security Notes are even released. On average, Onapsis delivers zero-day pre-patch protection to our customers 120 days before patches are available!

The Zero-Day Protection Gap

< 72 Hours

Threat Actor Exploitation

Adversaries reverse-engineer SAP security patches and launch active exploit campaigns in under 72 hours.

137 Days

Enterprise Patching Window

Security and SAP Basis teams take an average of 137 days to test and deploy manual vendor fixes.

Day 0

Onapsis Pre-Patch Shield

Onapsis Defend automatically updates with exclusive SAP exploitation detection rules for zero days, when discovered by Onapsis Research Labs.

Why Traditional Security Fails Against Zero-Day SAP Attacks

Conventional firewalls, endpoint EDR, and generic vulnerability scanners are all useful components of a defense-in-depth enterprise security strategy. However, their capabilities all stop at the SAP perimeter. To them, your SAP applications are unreadable black boxes.

When a zero-day vulnerability emerges in a core SAP application, generic security tools leave organizations exposed. SAP is extraordinarily complex and a closed ecosystem. Securing business-critical applications such as SAP requires deep knowledge that non-specialist security vendors lack. Criminal chatter regarding SAP zero-days has grown by 490%, accompanied by a 400% surge in targeted ransomware campaigns designed specifically to encrypt ERP data. Further, threat actors leveraging AI tooling can accelerate exploit creation dramatically and significantly increase risk for enterprises until an SAP Security Note is made available.

IT security professional monitoring systems in a server room
Cybersecurity incident response team reviewing security operations

Battle-Tested in Global Threat Campaigns

When zero-day SAP campaigns hit enterprise software, Onapsis provides immediate threat visibility and verified remediation within hours rather than weeks.

During major global zero-day events (such as the widespread exploitation of SAP NetWeaver Visual Composer components CVE-2025-31324 and CVE-2025-42999), Onapsis Research Labs led the global response:

  • Earliest Reconnaissance Detection: Onapsis sensors captured real-world exploit payloads weeks before public disclosure, allowing the Onapsis Research Labs to reconstruct the full remote code execution (RCE) attack path.
  • Root-Cause Patch Collaboration: Onapsis shared forensic analysis directly with the SAP Product Security Response Team, enabling the vendor to issue a revised patch addressing the underlying deserialization flaw.
  • Rapid Virtual Shielding: Onapsis customers received both immediate and continuous threat rule updates via Onapsis Defend, maintaining complete system protection while official vendor notes were authored and updated during a rapidly evolving zero-day campaign.

The Proven Authority in Zero-Day SAP Research

Our research team brings over 85 combined years of specialized cybersecurity experience, maintaining direct lockstep collaboration with global emergency response agencies and software vendors.

Zero-Day Disclosures

Onapsis researchers have discovered and responsibly disclosed over 1,000 zero-day vulnerabilities in enterprise applications.

of Critical SAP Vulnerabilities

In 2025 alone, Onapsis discovered 55% of all critical, CVSS 9.0+ HotNews vulnerabilities in SAP software.

US CISA Emergency Alerts

Federal cybersecurity agencies rely directly on Onapsis insights and telemetry to brief government officials, assist in publishing national threat advisories, and inform inclusion in CISA’s Known Exploited Vulnerabilities (KEV) catalog.

Threat Knowledgebase

Our proprietary intelligence engine indexes over 10,000 application-layer vulnerabilities, attack behaviors, and threat actor tactics, techniques, and procedures (TTPs).

Our continuous collaboration is formally recognized in the official SAP Security Researcher Acknowledgements, confirming our status as the leading, most prolific independent threat research contributor to SAP.

How Onapsis Delivers Zero-Day SAP Defense

The Onapsis Platform executes zero-day defense for our customers based heavily on the work of the Onapsis Research Labs:

Step 1:

Early Discovery & Intelligence Ingestion

The Onapsis Research Labs both conducts new SAP zero-day vulnerability discovery and monitors live threat actor activity across the world’s largest specialized SAP telemetry network. For both, the Onapsis Research Labs isolate novel attack payloads, zero-day indicators of compromise (IoCs), and multi-step exploitation chains long before public disclosure.

Step 2:

Pre-Patch Protection and Exploitation Early Warnings

The moment a zero-day vulnerability or active exploit vector is verified, Onapsis Research Labs help develop proprietary zero-day exploit rules that are deployed in Onapsis Defend. In parallel, Onapsis collaborates with SAP’s security and cyber intelligence teams to develop mitigations.

Step 3:

Automated Exposure Assessment

Whenever possible, Onapsis Assess is updated even before Security Notes are released with modules that can scan for discrete Indicators of Compromise (IoCs). When SAP releases Security Notes, security teams can execute automated scans across on-premises, cloud, and RISE with SAP environments to pinpoint vulnerable assets that require patching, prioritize higher-risk assets based on Onapsis Research Labs guidance and recommendations, and validate that all fixes have been executed correctly and completely – including any manual workarounds or configuration changes that are part of a Security Note.

What’s Needed to Defend SAP in the New AI Era?

Frontier AI models (like Mythos) are powering a surge in new vulnerability discovery, leading to thousands of new vulnerabilities. SAP, like all other software vendors, will face a larger backlog, leading to potential delays in patch delivery as well as more frequent, higher volume patch releases. Your enterprise exposure cycle will lengthen significantly, as the lag between discovery and patch availability will continue to worsen.

Meanwhile, state-sponsored and ransomware threat actors are rapidly operationalizing off-the-shelf AI to exploit SAP systems. Groups involved with the SAP zero-day in 2025 are already proficient AI users. Unfortunately, not every SAP system can be patched in a timely manner, and not every flaw will have a Security Note available in a timely manner. As time-to-exploit drops closer to zero, the enterprise needs to move significantly faster than they ever have before, and this is where the need to move at “machine speed” is derived.

Ultimately, to be successful in this AI era, enterprises must

  • Utilize continuous, high-fidelity SAP threat intelligence to monitor active threat actors and targets;
  • Leverage multi-checkpoint code security to protect against AI-generated custom SAP code vulnerabilities;
  • Deploy pre-patch SAP protection and compensating controls;
  • Implement agentic AI workflows to achieve more efficient exposure management and machine-speed defense against active SAP threats.

Without continuous, high-fidelity threat intelligence, all the rest of these requirements fail. This is where Onapsis and our Onapsis Research Labs fill the gap for the world’s largest enterprises in securing their mission-critical SAP landscapes as the key foundation for agentic SAP security orchestration.

Eliminate Your SAP Cybersecurity Blind Spot

Protect your business-critical applications from unpatched vulnerabilities, machine-speed attacks, and active zero-day campaigns.