SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud

SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, and Commerce Cloud

Enterprise software giant SAP has released a slew of security patches to address critical vulnerabilities in its NetWeaver Application Server ABAP, Approuter, and Commerce Cloud. The patches, part of SAP’s July 2026 security patch day, fix a total of 20 new and updated security notes that affect various components of the company’s software portfolio.

The most severe vulnerability, CVE-2026-44747, is a memory corruption bug in NetWeaver Application Server ABAP with a CVSS score of 9.9. If exploited successfully, an attacker could gain access to sensitive data, modify it, and even bring down the entire system. SAP security firm Onapsis warns that this vulnerability could be particularly nasty if left unpatched.

To mitigate this risk, SAP advises its customers to apply the fresh patches as soon as possible. However, in case of a delay or emergency situation, customers can temporarily disable all ICF nodes with a specific property in transaction SICF as a workaround. It’s essential for users to understand that this temporary fix is not a substitute for applying the patch and should only be used as an urgent measure.

Another critical vulnerability was addressed in Approuter, tracked as CVE-2026-27690 (CVSS score of 9.1). This HTTP request smuggling issue allows an unauthenticated attacker to send specially crafted HTTP requests that can lead to request-response desynchronization. SAP customers using non-Cloud Foundry environments are particularly vulnerable and must apply the latest patches immediately.

A third critical-severity vulnerability was discovered in Commerce Cloud, identified as CVE-2026-44761 (CVSS score of 9.1). This hardcoded credential issue stems from sample configuration scripts provided by SAP for development and testing purposes. If these scripts are executed in production environments without updating the default credentials, an attacker can exploit this flaw to obtain unauthorized access to sensitive data.

In related news, SAP has also updated a security note addressing a critical NetWeaver vulnerability initially patched in June to provide support for additional packages. Furthermore, six new security notes have been released to address high-severity security defects across various components of the SAP software portfolio.

The sheer number and severity of these vulnerabilities highlight the importance of regular software updates and thorough testing in production environments. It’s crucial for organizations using SAP software to stay on top of these patches and take necessary measures to protect their systems from potential threats.

To avoid falling victim to similar attacks, it is essential that users prioritize patching their systems as soon as possible. Regularly reviewing system configurations, monitoring network traffic, and keeping security software up-to-date can also help mitigate the risk of exploitation. By taking proactive steps, organizations can minimize the impact of these vulnerabilities and maintain a strong cybersecurity posture.


Source: SecurityWeek — 2026-07-14