SAP patched 19 vulnerabilities, including a critical bug leading to command execution, credential harvesting, and data tampering.