Breaking
SecurityDeveloping Story

SAP Patch Cycle Addresses Critical Risks

The latest SAP security update includes fixes for three critical vulnerabilities across its enterprise and cloud platforms.

··1 month ago·2 min read
a close up of a green light in a server
Photo by Tyler on Unsplash

SAP has released its July 2026 advisory, detailing patches for a total of 16 security vulnerabilities. This cycle addresses significant flaws impacting the company's core enterprise infrastructure, including the NetWeaver runtime environment and cloud-based middleware.

Critical Flaws in Infrastructure

The update prioritizes three critical vulnerabilities that could allow unauthorized access or service disruption. The first, CVE-2026-44747, is a memory corruption issue located within the NetWeaver Application Server ABAP. This platform serves as the development environment for many of the company's enterprise applications.

SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application.

— SAP

A second critical vulnerability, CVE-2026-27690, affects the SAP Approuter middleware. This Node.js-based tool is used for cloud-native apps on the Business Technology Platform. It allows unauthenticated actors to execute HTTP Request Smuggling, potentially leading to denial-of-service or unauthorized user data access. The final critical vulnerability, CVE-2026-44761, impacts SAP Commerce Cloud. It involves the use of default credentials, which may allow attackers to secure access tokens and interact with APIs.

Breakdown of Patch Data

  • 16 total vulnerabilities addressed in the July 2026 update.
  • 3 critical flaws patched across NetWeaver, Commerce Cloud, and AppRouter.
  • 6 high-severity vulnerabilities included in the release.
  • 7 medium-severity vulnerabilities included in the release.
  • 1 low-severity vulnerability included in the release.

Persistent Risks and Scope

While SAP has reported no evidence of active exploitation for these specific bugs, the company's widespread usage—powering 99 of the 100 largest global firms—remains a major factor in threat modeling. The Cybersecurity and Infrastructure Security Agency (has added 14 SAP security flaws) to its catalog of known exploited vulnerabilities since November 2021. Previous incidents include a in a supply chain attack against official npm packages and fixed 15 vulnerabilities in the previous month.

Implications for Enterprise Security

The discovery of these vulnerabilities suggests that organizations relying on large-scale enterprise software must maintain consistent patch cadences. Because these systems often store sensitive data and facilitate core business processes, the presence of memory corruption or default credential flaws could lead to significant operational disruptions if left unaddressed. Security teams may need to evaluate their exposure across both their core ERP environments and secondary middleware components to ensure that patches are effectively deployed.

#sap#cybersecurity#vulnerabilities#netweaver#enterprise

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories