SAP Patch Cycle Addresses Critical Risks
The latest SAP security update includes fixes for three critical vulnerabilities across its enterprise and cloud platforms.
SAP has released its July 2026 advisory, detailing patches for a total of 16 security vulnerabilities. This cycle addresses significant flaws impacting the company's core enterprise infrastructure, including the NetWeaver runtime environment and cloud-based middleware.
Critical Flaws in Infrastructure
The update prioritizes three critical vulnerabilities that could allow unauthorized access or service disruption. The first, CVE-2026-44747, is a memory corruption issue located within the NetWeaver Application Server ABAP. This platform serves as the development environment for many of the company's enterprise applications.
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application.
— SAP
A second critical vulnerability, CVE-2026-27690, affects the SAP Approuter middleware. This Node.js-based tool is used for cloud-native apps on the Business Technology Platform. It allows unauthenticated actors to execute HTTP Request Smuggling, potentially leading to denial-of-service or unauthorized user data access. The final critical vulnerability, CVE-2026-44761, impacts SAP Commerce Cloud. It involves the use of default credentials, which may allow attackers to secure access tokens and interact with APIs.
Breakdown of Patch Data
- 16 total vulnerabilities addressed in the July 2026 update.
- 3 critical flaws patched across NetWeaver, Commerce Cloud, and AppRouter.
- 6 high-severity vulnerabilities included in the release.
- 7 medium-severity vulnerabilities included in the release.
- 1 low-severity vulnerability included in the release.
Persistent Risks and Scope
While SAP has reported no evidence of active exploitation for these specific bugs, the company's widespread usage—powering 99 of the 100 largest global firms—remains a major factor in threat modeling. The Cybersecurity and Infrastructure Security Agency (has added 14 SAP security flaws) to its catalog of known exploited vulnerabilities since November 2021. Previous incidents include a in a supply chain attack against official npm packages and fixed 15 vulnerabilities in the previous month.
Implications for Enterprise Security
The discovery of these vulnerabilities suggests that organizations relying on large-scale enterprise software must maintain consistent patch cadences. Because these systems often store sensitive data and facilitate core business processes, the presence of memory corruption or default credential flaws could lead to significant operational disruptions if left unaddressed. Security teams may need to evaluate their exposure across both their core ERP environments and secondary middleware components to ensure that patches are effectively deployed.
Sources
- Trend analysis Original source
- CVE-2026-44761 Also reporting
- has added 14 SAP security flaws Also reporting
- July 2026 advisory Also reporting
- fixed 15 vulnerabilities Also reporting
- in a supply chain attack Also reporting
Continue Reading
APT28's HOOKEDGE Backdoor Refines Espionage Tactics
New HOOKEDGE backdoor targets European governments, evolving from HEADLACE to evade defenses.
AI Defense Pledge Draws 130 Signatories
OpenAI-led open letter urges global cyber defense surge as AI-enabled attacks grow more capable.
PaperCut Zero-Day Patch Urged
PaperCut Software warns of exploited zero-day in NG/MF, releases emergency patch and IoCs.