SAP has released July 2026 security patches addressing multiple vulnerabilities, including a critical out-of-bounds write flaw in SAP NetWeaver Application Server ABAP. Tracked as CVE-2026-44747 with a CVSS score of 9.9, the vulnerability allows authenticated attackers to leverage logical errors in memory management to corrupt memory, enabling unauthorized data access, modification, or system unavailability.
Onapsis noted that a temporary workaround involves disabling all ICF nodes with a specific property in transaction SICF, though this blocks opening transactions in SAP GUI for HTML. The firm strongly recommends installing the patched ABAP kernel version instead.
Two additional critical flaws were also fixed. CVE-2026-27690 (CVSS 9.1) is an HTTP request smuggling vulnerability in SAP Approuter deployments in non-Cloud Foundry environments that could expose user responses and trigger denial-of-service attacks. CVE-2026-44761 (CVSS 9.1) involves default OAuth 2.0 client credentials in SAP Commerce Cloud from sample configuration scripts that unauthenticated attackers could abuse.
Customers who removed the sample OAuth client or replaced the secret are not impacted. No evidence of active exploitation has been found, but immediate patching is advised.
