SAP’s July 2026 Security Patch Day addresses multiple high-impact vulnerabilities across its enterprise products, including a severe memory corruption issue in the SAP NetWeaver Application Server ABAP.
The most critical vulnerability, tracked as CVE-2026-44747, has a CVSS score of 9.9 and affects several SAP kernel releases used by NetWeaver AS ABAP.
SAP has categorized this issue as memory corruption. A low-privileged attacker could potentially exploit this flaw remotely, compromising the confidentiality, integrity, and availability of the affected environment.
SAP July 2026 Patch Day
Organizations should also prioritize CVE-2026-27690, a critical HTTP request smuggling vulnerability in SAP AppRouter versions prior to 20.10.
This issue carries a CVSS score of 9.1 and can be exploited remotely without authentication. Request-smuggling vulnerabilities can allow attackers to disrupt communication between front-end proxies and back-end applications, potentially bypassing security controls or exposing sensitive requests.
Another critical flaw is CVE-2026-44761, which impacts SAP Commerce Cloud versions HY_COM 2205, COM_CLOUD 2211, and 2211-JDK21.
This vulnerability arises from insecure sample credentials and has a CVSS score of 9.1. Default or sample credentials can provide an immediate entry point, especially when exposed services are improperly configured.
Additionally, SAP updated its June advisory regarding CVE-2026-40128, a critical directory traversal vulnerability in the SAP NetWeaver AS Java Web Container. This flaw also has a CVSS score of 9.0 and affects ENGINEAPI version 7.50.
CVE Details
| CVE | Product / Component | Vulnerability | Severity | CVSS |
|---|---|---|---|---|
| CVE-2026-44747 | SAP NetWeaver AS ABAP | Memory corruption | Critical | 9.9 |
| CVE-2026-27690 | SAP Approuter | HTTP request smuggling | Critical | 9.1 |
| CVE-2026-44761 | SAP Commerce Cloud | Insecure sample credentials | Critical | 9.1 |
| CVE-2026-40128 | SAP NetWeaver AS Java | Directory traversal | Critical | 9.0 |
| CVE-2026-40860 | SAP Integration Suite Edge Integration Cell | Multiple Apache Camel vulnerabilities | High | 8.8 |
| CVE-2026-40453 | Apache Camel in SAP Integration Suite | Third-party component flaw | High | 8.8 |
| CVE-2026-33454 | Apache Camel in SAP Integration Suite | Third-party component flaw | High | 8.8 |
| CVE-2026-0487 | SAProuter for Windows | DLL hijacking | High | 8.4 |
| CVE-2026-44752 | SAP NetWeaver AS Java Configuration Wizard | Cross-site scripting | High | 8.2 |
| CVE-2026-44745 | SAP Approuter | Open redirect | High | 8.1 |
| CVE-2026-43512 | Apache Tomcat in SAP Commerce Cloud | Multiple component vulnerabilities | High | 8.1 |
| CVE-2026-41293 | Apache Tomcat in SAP Commerce Cloud | Multiple component vulnerabilities | High | 8.1 |
| CVE-2026-43515 | Apache Tomcat in SAP Commerce Cloud | Multiple component vulnerabilities | High | 8.1 |
| CVE-2026-58233 | SAP ctsattach | Remote code execution | High | 7.6 |
| CVE-2026-44759 | SAP NetWeaver Enterprise Portal | Cross-site scripting | Medium | 6.1 |
| CVE-2026-44767 | UI5 webcomponents-base | Allowlist bypass / cross-origin CSS injection | Medium | 6.1 |
| CVE-2026-44769 | SAP S/4HANA Project Management | SQL injection | Medium | 5.5 |
| CVE-2026-44760 | SAP NetWeaver AS ABAP | Cross-site scripting | Medium | 4.7 |
| CVE-2026-44771 | SAP S/4HANA Draft Operation | Missing authorization check | Medium | 4.3 |
| CVE-2026-44770 | SAP S/4HANA Create Single Payment | Missing authorization check | Medium | 4.3 |
| CVE-2026-24315 | SAP Fiori Launchpad | Path traversal | Medium | 4.2 |
| CVE-2026-44768 | SAP CRM WebClient UI | Security misconfiguration | Medium | 4.1 |
| CVE-2026-44753 | SAP HANA XS Classic | Information disclosure | Low | 3.7 |
| CVE-2025-68161 | SAP NetWeaver AS Java / Apache Log4j | Potential third-party library vulnerability | Low | 3.3 |
Administrators should review the relevant SAP Security Notes, identify affected versions, and apply SAP’s fixes on priority. Teams should especially assess internet-facing Approuter deployments, Commerce Cloud installations, NetWeaver systems, and Windows-hosted SAProuter instances.
In parallel, organizations should remove sample accounts, rotate exposed credentials, validate reverse-proxy configurations, and monitor SAP logs for suspicious requests or unauthorized activity.
Gain browser-level visibility to expose decrypted phishing pages, speed investigations, and cut credential theft costs -> Power your SOC with ANY.RUN





