SAP warns of critical flaws in NetWeaver and Commerce Cloud

SAP has just issued a critical security update that affects its NetWeaver and Commerce Cloud platforms, leaving thousands of businesses vulnerable to cyber attacks. The German multinational software corporation has patched 16 vulnerabilities across multiple products, including three critical flaws in its flagship enterprise software.

These high-impact vulnerabilities could allow attackers to gain unauthorized access to sensitive data, disrupt system availability, or even trigger denial-of-service attacks on targeted systems. One of the critical issues stems from a memory corruption security flaw in NetWeaver Application Server ABAP, which is used by thousands of organizations worldwide as their runtime environment and application server.

An attacker with authentication privileges could exploit this weakness to cause memory corruption, resulting in unauthorized data access, modification, or system unavailability. This has significant implications for confidentiality, integrity, and availability of the application, making it a top priority for SAP to address this issue. The company’s July 2026 security advisory also lists fixes for six high-severity flaws, seven medium-severity ones, and one low-severity vulnerability.

Another critical flaw was discovered in the SAP Commerce Cloud enterprise e-commerce platform. This vulnerability allows attackers to gain access to valid tokens and read or modify data via certain APIs due to default credentials being left unchanged by users. The company has stated that it has yet to find evidence of this vulnerability being exploited in attacks, but given its severity, organizations should prioritize patching as soon as possible.

SAP’s latest security updates come on the heels of a series of critical vulnerabilities patched just last month. In June 2026, the company fixed 15 vulnerabilities across multiple products, and attackers compromised several official SAP npm packages to steal credentials from developers’ systems. This highlights the importance for organizations to stay up-to-date with the latest security patches and updates.

Given the severity of these vulnerabilities and the track record of SAP’s products being exploited by attackers, it is essential for businesses to prioritize patching and ensure that their systems are secure. Security teams should also test every layer of their environment before attackers do, as a recent whitepaper from Picus shows how breach and attack simulation can help improve detection rates.

As one of the world’s leading software corporations, SAP’s products serve 99 of the 100 largest companies worldwide, generating total revenues exceeding €36 billion in fiscal year 2025. With such a vast user base, it is crucial for organizations to take immediate action to patch these vulnerabilities and protect themselves from potential cyber attacks.

To stay secure, we recommend that organizations:

* Prioritize patching as soon as possible

* Regularly review and update their security configurations

* Conduct regular breach and attack simulation tests to improve detection rates

* Stay informed about the latest security patches and updates

By taking these steps, businesses can minimize their risk of being compromised by attackers and protect themselves from potential data breaches.


Source: Bleeping Computer — 2026-07-14