SecurityBridge - Experts & Thought Leaders

Latest SecurityBridge news & announcements

SecurityBridge names Hügels as CTO for SAP Security

SecurityBridge, the Cybersecurity Command Center for SAP, announces the promotion of Holger Hügel to Chief Technology Officer (CTO). Hügel previously served as director of product management and will now oversee the company’s SAP security platform's technological development and strategic innovation. The leadership appointment follows Jesper Zerlang's transition to CEO earlier this year. Company founders Christoph Nagy and Ivan Mans, who previously held the CEO and CTO roles respectively, will step back from day-to-day executive leadership but remain closely involved in shaping the company’s strategic direction. Complex technology environments Hügel brings more than 25 years of experience in SAP and IT operations, with a career focused on bridging business requirements with complex technology environments. At SecurityBridge, he has been instrumental in advancing the company’s SAP security platform and expanding its capabilities to help enterprises defend critical systems against evolving cyber threats. “I’m excited to continue advancing the SAP security vision established by the company’s founders,” Hügel said. “There is significant innovation potential ahead for the platform, and I look forward to working with our team to further strengthen how organisations secure their SAP environments.” Long-term innovation Before joining SecurityBridge in 2023, Hügel held leadership roles at SECUDE, SmartShift, and Realtech, where he focused on SAP S/4HANA environments, SAP ERP, business development, and strategic partnerships. SecurityBridge co-founder Christoph Nagy said Hügel’s deep experience in SAP security and knowledge of the company’s technology made him a natural choice for the role. “Holger has extensive expertise in SAP security and a strong understanding of our platform,” Nagy said. “With him leading technology development as CTO, the founders can focus more on supporting long-term innovation and product vision.”

SecurityBridge appoints Jesper Zerlang as CEO

SecurityBridge, a provider of cybersecurity solutions for SAP, announces the appointment of Jesper Zerlang as Chief Executive Officer, effective January 1, 2026. Zerlang transitions from his role as Chairman of the Board, a position he has held for the past 12 months, as the company enters its next phase of international expansion, backed by funds advised by BU Bregal Unternehmerkapital (BU). SecurityBridge protects SAP environments for large enterprises by reducing cyber risk across mission-critical SAP landscapes. The company is trusted by global customers to safeguard systems that power core operations, financial processes, supply chains, and digital transformation programs. Customer-driven initiatives “SecurityBridge is uniquely positioned at the intersection of cybersecurity and SAP – a domain I know deeply and care about profoundly,” said Jesper Zerlang, CEO of SecurityBridge. “Over the past year, as Chairman, I have seen firsthand the strength of the team, the technology, and the outcomes we deliver for customers. With BU’s support and a clear ambition to scale internationally, I am excited to step into the CEO role to accelerate global impact while raising the bar on trust and customer outcomes.” SecurityBridge founders Christoph Nagy and Ivan Mans will transition out of their day-to-day operational roles as CEO and CTO, respectively. They will remain strategically central to the business in pivotal roles focused on product evangelism and high-impact, customer-driven initiatives, leveraging their SAP engineering depth, credibility, and long-term product vision. Long-term product vision “SecurityBridge has grown into a remarkable company with a strong foundation and a clear mission,” said Nagy, Co-Founder of SecurityBridge. “This transition strengthens the company’s ability to scale globally while allowing us to focus where we create the greatest value for customers: product leadership, innovation, and engagement with the SAP ecosystem.” “We are fully supportive of this exciting transition and look forward to contributing in roles that amplify our technical focus and customer impact. SecurityBridge’s opportunity ahead is significant, and this step positions the company strongly for the next stage,” added Ivan Mans, Co-Founder of SecurityBridge.

Critical SAP vulnerability: Code injection threat

SecurityBridge, creator of the Cybersecurity Command Center for SAP, announced that the SecurityBridge Threat Research Labs uncovered a critical SAP vulnerability rated a 9.9 out of 10 severity, and gave its customers advanced notice on October 30, 2025, to update detection signatures before the vulnerability was publicly disclosed.  In total, the Threat Research Labs uncovered three vulnerabilities that were among the 25 new and updated SAP Security Notes SAP published for its November Patch Day.  Contained in the SAP Patch Day alert, the HotNews note 3668705 – [CVE-2025-42887] Code Injection vulnerability in SAP Solution Manager describes how a remote-enabled function module can be misused to inject malicious code, resulting in complete system control. Public patch A public patch for this vulnerability has been released, which might speed up reverse-engineering and exploit development, so patching soon is advised. In addition to the highest priority category discovered, the Threat Research Labs found the following two vulnerabilities, also released within the SAP Patch Day notes: Medium priority: note 3643337 – [CVE-2025-42882] Missing Authorisation check in SAP NetWeaver Application Server for ABAP 4.3 Low priority: note 3634053 – [CVE-2025-42883] Insecure File Operations vulnerability in SAP NetWeaver Application Server for ABAP (Migration Workbench) Code-injection vulnerability "When we discover a vulnerability that scores a 9.9 out of 10 priority rating, we know we're looking at a threat that could give attackers complete system control," said Joris van de Vis, Director of Security Research, SecurityBridge. "CVE-2025-42887 is particularly dangerous because it allows to inject code from a low-privileged user, which leads to a full SAP compromise and all data contained in the SAP system.” “This code-injection vulnerability in SAP Solution Manager represents exactly the kind of critical attack surface weakness that our Threat Research Labs work tirelessly to identify and eliminate. SAP systems are the backbone of business operations, and vulnerabilities like this remind us why proactive security research is non-negotiable." Uncovering the most critical SAP vulnerabilities The SecurityBridge Threat Research Labs has a history of uncovering the most critical SAP vulnerabilities: In September 2025, the company discovered a Critical SAP S/4HANA code injection vulnerability (CVE-2025-42957), rated 9.9 out of 10 in severity.  In August 2025, the team discovered three vulnerabilities, two of which were rated 9.9 out of 10 in severity: [CVE-2025-42950] Code Injection Vulnerability in SAP Landscape Transformation (Analysis Platform) [CVE-2025-42957] Code Injection vulnerability in SAP S/4HANA (Private Cloud or On-Premise) [CVE-2025-42946] Directory Traversal vulnerability in SAP S/4HANA (Bank Communication Management) The company has updated the SecurityBridge Platform to ensure customers are insulated from known vulnerabilities. SecurityBridge's Patch Management offers invaluable insights into existing patching gaps within SAP landscapes, a complete list of today’s new vulnerabilities, and an overview.