< Back to all clusters
[TECHNOLOGY] · Germany · 5 sources

SAP releases patches for critical NetWeaver ABAP and other security flaws

SAP announced its July 2026 security update, publishing 16 new Security Notes and addressing three critical vulnerabilities. The most severe, CVE‑2026‑44747 (CVSS 9.9), is an out‑of‑bounds write flaw in SAP NetWeaver Application Server ABAP that could allow an authenticated attacker with low privileges to read, modify or delete data and cause system crashes. Two additional critical flaws were patched: CVE‑2026‑27690 (CVSS 9.1), an HTTP request/response smuggling issue in SAP Approuter, and CVE‑2026‑44761 (CVSS 9.1), a default‑credential weakness in SAP Commerce Cloud that could let an unauthenticated attacker obtain a valid OAuth 2.0 token and access APIs. SAP recommends installing the updated ABAP kernel and removing any default OAuth clients; a temporary workaround of disabling certain ICF nodes is not suitable for all customers. No evidence of active exploitation has been reported. Customers are urged to apply the patches promptly, audit their environments for the affected components, and enforce least‑privilege access controls.