SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-66768

CRITICAL · CVSS 9 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the SAP GUI for Java, where improper enforcement of the trust level policy allows low-privileged attackers to exploit connected backend systems. This could lead to arbitrary command execution on the victim's machine, severely compromising the confidentiality, integrity, and availability of the system. Organizations using SAP GUI for Java should prioritize immediate remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66768
Severity
CRITICAL
CVSS
9
EPSS
0.32%
Java

Original NVD Description

SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system.