SAP fixes critical flaws in NetWeaver and Commerce Cloud
SAP has released a security patch addressing 15 vulnerabilities across its NetWeaver and Commerce Cloud platforms. The patch includes four critical flaws, primarily focused on authentication bypass and memory corruption, which could lead to unauthorized access and system disruption. Organizations utilizing these SAP products are urged to prioritize patching to mitigate these risks.
SAP’s June 2026 Security Patch package addresses a significant number of vulnerabilities within its core application platforms. The vulnerabilities primarily target SAP NetWeaver, a middleware stack used for various business applications like ERP systems, and SAP Commerce Cloud, an e-commerce platform. The identified flaws include critical issues like CVE-2026-44748, a SAML authentication bypass vulnerability, and CVE-2026-27671, a memory corruption flaw, both with high CVSS scores. These vulnerabilities could allow attackers to gain unauthorized access to sensitive user data and disrupt system operations.
Beyond the critical vulnerabilities, the patch also resolves several high-severity issues, including Apache Tomcat flaws within Commerce Cloud and authorization bypass problems in NetWeaver AS ABAP. The security bulletin details a range of other vulnerabilities, such as SQL injection and cross-site scripting, across multiple SAP products. SAP emphasizes the importance of immediate patching, particularly for the SAML authentication flaw and the memory corruption issue, given their potential for severe impact on enterprise environments.