Sunday, September 13, 2026

SAP July 2026 Patch Day Fixes Critical NetWeaver, Approuter, and Commerce Cloud Vulnerabilities

SAP’s July 2026 Security Patch Day addresses multiple high-impact vulnerabilities across its enterprise products, including a severe memory corruption issue in the SAP NetWeaver Application Server ABAP.

The most critical vulnerability, tracked as CVE-2026-44747, has a CVSS score of 9.9 and affects several SAP kernel releases used by NetWeaver AS ABAP.

SAP has categorized this issue as memory corruption. A low-privileged attacker could potentially exploit this flaw remotely, compromising the confidentiality, integrity, and availability of the affected environment.

SAP July 2026 Patch Day

Organizations should also prioritize CVE-2026-27690, a critical HTTP request smuggling vulnerability in SAP AppRouter versions prior to 20.10.

This issue carries a CVSS score of 9.1 and can be exploited remotely without authentication. Request-smuggling vulnerabilities can allow attackers to disrupt communication between front-end proxies and back-end applications, potentially bypassing security controls or exposing sensitive requests.

Another critical flaw is CVE-2026-44761, which impacts SAP Commerce Cloud versions HY_COM 2205, COM_CLOUD 2211, and 2211-JDK21.

This vulnerability arises from insecure sample credentials and has a CVSS score of 9.1. Default or sample credentials can provide an immediate entry point, especially when exposed services are improperly configured.

Additionally, SAP updated its June advisory regarding CVE-2026-40128, a critical directory traversal vulnerability in the SAP NetWeaver AS Java Web Container. This flaw also has a CVSS score of 9.0 and affects ENGINEAPI version 7.50.

CVE Details

CVEProduct / ComponentVulnerabilitySeverityCVSS
CVE-2026-44747SAP NetWeaver AS ABAPMemory corruptionCritical9.99.99.9
CVE-2026-27690SAP ApprouterHTTP request smugglingCritical9.19.19.1
CVE-2026-44761SAP Commerce CloudInsecure sample credentialsCritical9.19.19.1
CVE-2026-40128SAP NetWeaver AS JavaDirectory traversalCritical9.09.09.0
CVE-2026-40860SAP Integration Suite Edge Integration CellMultiple Apache Camel vulnerabilitiesHigh8.88.88.8
CVE-2026-40453Apache Camel in SAP Integration SuiteThird-party component flawHigh8.88.88.8
CVE-2026-33454Apache Camel in SAP Integration SuiteThird-party component flawHigh8.88.88.8
CVE-2026-0487SAProuter for WindowsDLL hijackingHigh8.48.48.4
CVE-2026-44752SAP NetWeaver AS Java Configuration WizardCross-site scriptingHigh8.28.28.2
CVE-2026-44745SAP ApprouterOpen redirectHigh8.18.18.1
CVE-2026-43512Apache Tomcat in SAP Commerce CloudMultiple component vulnerabilitiesHigh8.18.18.1
CVE-2026-41293Apache Tomcat in SAP Commerce CloudMultiple component vulnerabilitiesHigh8.18.18.1
CVE-2026-43515Apache Tomcat in SAP Commerce CloudMultiple component vulnerabilitiesHigh8.18.18.1
CVE-2026-58233SAP ctsattachRemote code executionHigh7.67.67.6
CVE-2026-44759SAP NetWeaver Enterprise PortalCross-site scriptingMedium6.16.16.1
CVE-2026-44767UI5 webcomponents-baseAllowlist bypass / cross-origin CSS injectionMedium6.16.16.1
CVE-2026-44769SAP S/4HANA Project ManagementSQL injectionMedium5.55.55.5
CVE-2026-44760SAP NetWeaver AS ABAPCross-site scriptingMedium4.74.74.7
CVE-2026-44771SAP S/4HANA Draft OperationMissing authorization checkMedium4.34.34.3
CVE-2026-44770SAP S/4HANA Create Single PaymentMissing authorization checkMedium4.34.34.3
CVE-2026-24315SAP Fiori LaunchpadPath traversalMedium4.24.24.2
CVE-2026-44768SAP CRM WebClient UISecurity misconfigurationMedium4.14.14.1
CVE-2026-44753SAP HANA XS ClassicInformation disclosureLow3.73.73.7
CVE-2025-68161SAP NetWeaver AS Java / Apache Log4jPotential third-party library vulnerabilityLow3.33.33.3

Administrators should review the relevant SAP Security Notes, identify affected versions, and apply SAP’s fixes on priority. Teams should especially assess internet-facing Approuter deployments, Commerce Cloud installations, NetWeaver systems, and Windows-hosted SAProuter instances.

In parallel, organizations should remove sample accounts, rotate exposed credentials, validate reverse-proxy configurations, and monitor SAP logs for suspicious requests or unauthorized activity.

Gain browser-level visibility to expose decrypted phishing pages, speed investigations, and cut credential theft costs -> Power your SOC with ANY.RUN

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News