
Onapsis Research Labs and Recorded Future analyzed over 1.2 million threat-intelligence events (spanning 2023 through H1 2026) to answer a practical question: How is the SAP threat landscape evolving, and how can defenders protect themselves?
The findings point to speed across the threat landscape:
- Collapsed SAP Exploit Timelines: The median time between an SAP Security Note release and the first verified public exploitation or proof-of-concept collapsed from 489 days (2021 patches) to 1 to 3 days (2025 and 2026 patches).
- Broadened SAP Ransomware and Extortion Interest: Ransomware and extortion interest expanded from 1 dominant group in 2022 to 22 distinct groups mentioned together with SAP in H1 2026 (30 groups across the full period).
- Surging Underground SAP Threat Discourse: SAP threat discussions in underground sources more than doubled from H1 2023 to H1 2025.
While SAP patches promptly, a critical gap has opened between how quickly flaws are weaponized and how quickly organizations apply the fixes.
Don’t leave your SAP landscape exposed. Register now to secure your place and receive the full research report.

