TL;DR: ERP and business application environments are facing repeated CVSS 9.9 exposures, direct exploitation of Oracle EBS and PeopleSoft, and attack paths that increasingly rely on valid access rather than classic vulnerability chaining, according to Pathlock’s review of H1 2026. The pattern shows that ERP defence now depends on continuous exposure management, application-layer monitoring, and tighter governance of both human and non-human identities.
NHIMG editorial — based on content published by Pathlock: H1 2026 showed ERP and business applications becoming increasingly attractive cyber targets
By the numbers:
- The PeopleSoft campaign affected more than 100 organizations.
- Salesforce reported that compromised Gainsight tokens and connections enabled unauthorized access between October 23 and November 19, 2025.
Questions worth separating out
Q: What breaks when ERP access is treated as safe after login?
A: The control model breaks because authentication does not prove that a payment, entitlement change, or data export is legitimate.
Q: Why do service accounts and trusted integrations increase ERP risk?
A: They increase risk because they create durable paths into business applications that often receive less review than human logins.
Q: How can teams tell whether ERP access controls are actually working?
A: Measure whether high-privilege accounts are forced through the IdP, whether sensitive actions are logged at a granular level, and whether masking prevents unnecessary data exposure.
Practitioner guidance
- Inventory internet-facing ERP and business application exposure Continuously map externally reachable ERP components, application gateways, and admin interfaces, then prioritise systems with known internet exposure for accelerated review and compensating controls.
- Correlate identity events with application transactions Send ERP transaction data, privilege changes, payment actions, and master-data updates into detection workflows so security teams can distinguish valid logins from suspicious business activity.
- Review trusted integrations as governed privileges Reassess service accounts, API tokens, partner connections, and guest-user configurations on a fixed schedule, with explicit ownership, purpose, and offboarding criteria for each connection.
What's in the full article
Pathlock's full analysis covers the operational detail this post intentionally leaves for the source:
- Patch-cycle-by-patch-cycle breakdown of SAP’s H1 2026 critical disclosures and affected components
- Attack-path detail from Oracle EBS and PeopleSoft exploitation, including how automation changed the threat model
- Application-layer monitoring and transaction-context examples that help distinguish legitimate from malicious ERP activity
- Guidance on how to harden guest access, tokens, and trusted integrations without relying on authentication alone
ERP security in 2026: what practitioners should re-evaluate now?
Explore further
ERP security has become an identity problem as much as an application problem. The article shows that valid access, trusted integrations, and over-permissive accounts can be more dangerous than a headline vulnerability because they sit inside normal control assumptions. IAM and PAM teams need to extend governance from authentication into transaction authorisation and runtime monitoring. The practitioner conclusion is that application access must be evaluated by business action, not login success.
A question worth separating out:
Q: Which control matters most after an ERP breach or exploit?
A: Containment depends on limiting what the compromised identity or integration can do next. That means narrowing privileges, isolating sensitive functions, validating trusted connections, and checking whether the attacker used application logic rather than host-level malware. In practice, the right response is to protect the business process before the attacker completes the next transaction.
👉 Read our full editorial: ERP security in 2026: why critical apps are now top targets