What changed
On the security side, SAP released 15 new security notes on March 10. Two are rated HotNews. The most dangerous is a CVSS 9.8 code injection vulnerability in SAP Quotation Management Insurance (FS-QUO) - caused by an outdated Apache Log4j 1.2 library in the scheduler module. It allows unauthenticated remote code execution - no credentials needed. The second HotNews fix (CVSS 9.1) addresses insecure deserialization in NetWeaver Enterprise Portal. A CVSS 7.7 denial-of-service vulnerability affects SAP Supply Chain Management. Additional fixes cover SSRF, SQL injection, XSS, missing authorization checks, and DLL hijacking across NetWeaver, Business One, S/4HANA, Business Warehouse, and SAP GUI for Windows.
Two days later, S/4HANA Cloud Public Edition 2602.1 went live as a mandatory update. Joule AI-assisted situation handling is GA - Joule evaluates company policies and recommends actions. AI-assisted error explanation for cost accounting walks users through step-by-step fixes. The new Fiori shell bar is now the default interface, with opt-out only until Q3 2026. Joule Agent Builder is GA - customers can build custom AI agents. Beta features include smart helpers that execute repetitive Fiori tasks and AI-assisted Easy Fill for forms. SAP also published an 8-part UX blog series covering Joule Deep Research, Joule Action Bar, Document AI in SAP Mobile Start, a Payroll Agent in SuccessFactors, and an accrual proposal agent that automates period-end close activities.
Why this matters for you
You are handling two fundamentally different testing priorities in the same sprint. The Log4j vulnerability is unauthenticated and remotely exploitable - your Basis team needs a patching window and your QA team needs regression on every landscape running FS-QUO, Enterprise Portal, or Supply Chain Management. Simultaneously, the 2602.1 release expands regression scope across the board: the Fiori shell bar default changes the UI for every user, and Joule is now making financial recommendations in cost accounting that someone needs to validate.
The deeper concern is structural. AI features are no longer optional add-ons. Joule is embedded in financial workflows. Custom agents are being built by customers. An accrual agent automates period-end close. These are non-deterministic systems producing recommendations that affect financial reporting - traditional pass/fail testing doesn't cover this. If your landscape spans cloud and on-premises, the innovation gap widens further: AI features, smart helpers, and Agent Builder are cloud-only, creating a two-speed testing reality.
What you can do
For patches: prioritize the Log4j fix (FS-QUO) this week. Coordinate with Basis on the Enterprise Portal deserialization fix. Add the Supply Chain Management DoS vulnerability to your priority list. For the release: start regression on the Fiori shell bar now - opt-out closes Q3 2026. Build a testing approach for AI-assisted recommendations in cost accounting: define what correct means for Joule's suggestions against your specific company policies, then test against those definitions. If your organization is using Joule Agent Builder, establish governance for custom agent testing before agents proliferate.
Watch out for
The 2602.1 release naming is confusing even among experienced SAP leaders. Confirm which features are GA versus beta before building test plans.