CVE-2026-40137: SAP SE Business Server Pages Application Taf Applauncher

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.

Affected products

  • SAP SE Business Server Pages Application Taf Applauncher: version 758 only

Published 2026-05-12. Last modified 2026-06-17.