SAP patches critical NetWeaver ABAP flaw with CVSS 9.9 severity rating

SAP releases July 2026 security updates for a critical memory corruption flaw in NetWeaver ABAP and two additional CVSS 9.1 vulnerabilities.

CSBadmin
1 Min Read

SAP has released July 2026 security patches addressing multiple vulnerabilities, including a critical out-of-bounds write flaw in SAP NetWeaver Application Server ABAP. Tracked as CVE-2026-44747 with a CVSS score of 9.9, the vulnerability allows authenticated attackers to leverage logical errors in memory management to corrupt memory, enabling unauthorized data access, modification, or system unavailability.

Onapsis noted that a temporary workaround involves disabling all ICF nodes with a specific property in transaction SICF, though this blocks opening transactions in SAP GUI for HTML. The firm strongly recommends installing the patched ABAP kernel version instead.

Two additional critical flaws were also fixed. CVE-2026-27690 (CVSS 9.1) is an HTTP request smuggling vulnerability in SAP Approuter deployments in non-Cloud Foundry environments that could expose user responses and trigger denial-of-service attacks. CVE-2026-44761 (CVSS 9.1) involves default OAuth 2.0 client credentials in SAP Commerce Cloud from sample configuration scripts that unauthenticated attackers could abuse.

Customers who removed the sample OAuth client or replaced the secret are not impacted. No evidence of active exploitation has been found, but immediate patching is advised.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.