SAS® Web Application Server 9.53 (SAS® 9.4 TS1M9) hot fixes address security vulnerabilities


Severity: Critical/High/Medium/Low


Description: SAS Web Application Server 9.53 hot fixes address the following security vulnerabilities. These hot fixes are cumulative; therefore, only the most recent hot fix is required to address all vulnerabilities listed below.

See SAS KB0046220 for the current supported Apache HTTP Server (httpd), OpenSSL and Apache Tomcat versions in SAS 9.4. 

 

Addressed in hot fix P6T005

CVE-2026-24880CVE-2026-25854CVE-2026-29129CVE-2026-29145CVE-2026-29146
CVE-2026-32990CVE-2026-34197CVE-2026-34483CVE-2026-34486CVE-2026-34487
CVE-2026-34500CVE-2026-40466CVE-2026-41043CVE-2026-41044CVE-2026-41284
CVE-2026-41293CVE-2026-42253CVE-2026-42498CVE-2026-42588CVE-2026-43512
CVE-2026-43513CVE-2026-43514CVE-2026-43515CVE-2026-45505CVE-2026-46605
CVE-2026-49270CVE-2026-49432CVE-2026-50229CVE-2026-50734CVE-2026-53404
CVE-2026-53434CVE-2026-53916CVE-2026-53917CVE-2026-55276CVE-2026-55955
CVE-2026-55956    

 

Addressed in hot fix P6T004

CVE-2026-24733CVE-2026-24734CVE-2026-33227CVE-2026-33453CVE-2026-39304
CVE-2025-66614    

 

Addressed in hot fix P6T003

CVE-2024-6763CVE-2025-68161

 

Addressed in hot fix P6T002

CVE-2025-48989CVE-2025-55752CVE-2025-55754CVE-2025-61795

 

Addressed in hot fix P6T001

CVE-2024-6763CVE-2025-27533CVE-2025-48734CVE-2025-31650CVE-2025-31651
CVE-2025-46701CVE-2025-48976CVE-2025-48988CVE-2025-49124CVE-2025-49125
CVE-2025-49215CVE-2025-52520CVE-2025-53506  

 

Potential Impact: See the CVE records for additional information.