news.mlab.sh
Back to the feed
vulnerability

SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud

Critical
Summary

SAP released 19 security patches on July 26th, 2026, addressing critical vulnerabilities across several of its flagship products, including NetWeaver, Approuter, and Commerce Cloud. The most severe vulnerability, CVE-2026-44747, is a memory corruption bug in NetWeaver Application Server ABAP that could lead to data modification and system unavailability. SAP advises immediate patching, with a temporary workaround available for NetWeaver.

SAP announced the release of 19 security patches on July 26th, 2026, addressing critical vulnerabilities within its suite of enterprise software products. These patches are part of the company’s regular security update cycle. The most serious vulnerability, CVE-2026-44747, is a memory corruption bug found in NetWeaver Application Server ABAP, carrying a CVSS score of 9.9. Successful exploitation of this defect could allow an attacker to access and modify data, and potentially cause system unavailability. SAP’s security firm, Onapsis, recommends applying these patches immediately.

Another critical vulnerability, CVE-2026-27690, affects Approuter deployments in non-Cloud Foundry environments and allows an unauthenticated attacker to send a specially crafted HTTP request, leading to request-response desynchronization.

Furthermore, a critical vulnerability in Commerce Cloud, tracked as CVE-2026-44761, stems from hardcoded credentials within sample configuration scripts previously available in the SAP Help Portal. These scripts, when executed and the resulting OAuth2 client retained in production, could enable an unauthenticated attacker to obtain an access token and subsequently read and tamper with system data. SAP notes that customers who removed these sample clients or replaced the hardcoded secret with a strong, unique value are not affected.

Beyond these core vulnerabilities, the company also updated a security note addressing a previously patched NetWeaver vulnerability for additional packages. Six additional security notes address medium- and low-severity flaws across Integration Suite (Edge Integration Cell), SAProuter, NetWeaver Application Server Java (Configuration Wizard), Approuter, Commerce Cloud, and Change and Transport System Attach Tool (ctsattach). These notes include patches for multiple Apache Camel and Apache Tomcat security bugs.

The release highlights the ongoing need for vigilance and proactive security management within organizations utilizing SAP’s products.

Read the full article at SecurityWeek