Saturday, October 10, 2026

Ypê Runs SAP on Third-Party Support, Exposing Critical ERP to Unpatched Vulnerabilities

Brazilian consumer goods giant Ypê operates its SAP ERP system on Rimini Street support instead of official vendor maintenance. The configuration leaves the company vulnerable to known security flaws that SAP patches but third-party providers may not replicate at the same speed or scope.

Ypê Runs SAP on Third-Party Support, Exposing Critical ERP to Unpatched Vulnerabilities
Image generated by AI for illustrative purposes. Not actual footage or photography from the reported events.

Ypê, the Brazilian consumer goods manufacturer whose products reach over 95% of Brazilian households, operates its SAP enterprise resource planning system on third-party support from Rimini Street rather than official SAP maintenance.

The arrangement exposes the company's core operational systems to known cybersecurity vulnerabilities. SAP releases security patches for documented Common Vulnerabilities and Exposures (CVEs) through its standard support channels. Third-party support providers like Rimini Street may not replicate these patches at the same speed or with the same coverage.

ERP systems control critical business functions including financial reporting, supply chain operations, inventory management, and customer data. A compromised ERP environment can halt production, expose proprietary formulas, or leak customer information.

Companies choose third-party ERP support to reduce costs. Rimini Street charges roughly 50% less than SAP's standard maintenance fees. For large enterprises running complex SAP installations, this can mean annual savings of several million dollars.

The trade-off comes in security patch delivery. SAP releases monthly security notes and emergency patches for critical vulnerabilities. Third-party providers typically focus on break-fix support rather than proactive security updates. They may provide custom code fixes for specific issues but don't automatically deliver SAP's full patch catalog.

The risk calculus shifts as threat actors increasingly target ERP systems. The 2025 Onapsis ERP Threat Report documented a 34% increase in attacks specifically targeting SAP vulnerabilities. Attackers know that companies on third-party support often run outdated patch levels.

Brazil's General Data Protection Law (LGPD) requires companies to implement appropriate security measures for personal data. A breach stemming from known but unpatched vulnerabilities could trigger regulatory action and fines up to 2% of revenue.

Ypê operates in a competitive fast-moving consumer goods market where operational continuity directly impacts market share. Any ERP downtime ripples through production schedules, retail distribution, and cash flow management.

The company faces a decision point: accept ongoing security risk to preserve cost savings, or return to vendor support to close the vulnerability gap.

What we know · the intelligence behind this page
Live from the substrate
What we're seeing
Agentic Enterprise Software Consolidates: Big Platforms Push Autonomy While Startups Get Absorbed
Enterprise software is shifting toward autonomous, AI-agent-driven products. SAP (Autonomous Enterprise, Joule), Meta (a new Enterprise Platform led by ex-MongoDB CEO Chirantan Desai) and UiPath (raised guidance) are pushing from the top. Meanwhile AI-security and governance startups are being acquired (Fortinet–Virtue AI, Harvey–Guardrails AI, Tiny–Oso Cloud) and seed-stage agent companies keep raising capital (Dextr, Latitude, Groq). Investors such as Norwest's Sean Jacobsohn see finance and ERP back-office software as the easier area to disrupt. Trust and enforced governance are treated as preconditions for regulated sectors like finance, and AI is judged unreliable for calculations.
Our read on the data ›
Signals we're tracking
EPKINLY Regulatory-Clinical Success Cascade
High probability of expanded label indications, additional combination approvals, and competitive positioning strength in follicular lymphoma market. Predicts positive commercial uptake and potential accelerated review for related indications.
Patterns we're watching ›
Where sources disagree
ING Group
Both facts record the same metric (shares_outstanding) for ING Group at the identical observation date (2025-12-31). FACT A states 2,902,437,688 shares; FACT B states 2,902 million shares (2,902,000,000). The difference is 437,688 shares (~0.015%). This is a genuine value conflict, though the discrepancy appears to result from FACT B rounding to the nearest million while FACT A provides the precise count.
We flag conflicts openly ›
Recently verified
✓ Checked against the original source
4,986
facts traced to their source — and we flag the ones that don't hold up.
101 entities tracked4,986 facts checked against source5,365 source documents archived
Query this data → isubstrate.com