Skip to content

SAP Closes Three Critical Security Vulnerabilities in NetWeaver, AppRouter and Commerce Cloud

Bottom line: SAP patches three critical security vulnerabilities (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761) in NetWeaver, AppRouter and Commerce Cloud that enable memory corruption, DoS attacks and token theft.

In July 2026, SAP closed a total of 16 security vulnerabilities, including three critical flaws in core product components. Relevant for CISOs: Two of the critical flaws enable unauthenticated attack vectors or data access using pre-installed credentials.

As part of its monthly patch day in July 2026, SAP closed 16 security vulnerabilities. Three were classified as critical: CVE-2026-44747 in NetWeaver Application Server ABAP, CVE-2026-27690 in SAP AppRouter and CVE-2026-44761 in SAP Commerce Cloud.

CVE-2026-44747 affects the NetWeaver Application Server ABAP and describes a buffer overflow vulnerability. An authenticated attacker can exploit logical errors in memory management to cause memory corruption. This jeopardizes the confidentiality, integrity and availability of the application. CVE-2026-27690 affects AppRouter, a Node.js-based middleware library of the SAP Business Technology Platform. Unauthenticated attackers can use specially crafted HTTP requests to access user responses or trigger denial-of-service attacks. CVE-2026-44761 in Commerce Cloud allows attackers to obtain valid access tokens via pre-configured credentials and read or modify data via certain APIs.

In addition to the critical flaws, six vulnerabilities with high severity, seven with medium severity and one with low severity were patched. The range includes DLL hijacking, missing permission checks, remote code execution, cross-site scripting, SQL injection and information disclosure. According to SAP, there are currently no indications of active exploitation of the new vulnerabilities.

However, the U.S. cybersecurity agency CISA warns: Since November 2021, 14 SAP security vulnerabilities have been added to the catalog of known exploited vulnerabilities, two of which have been abused by ransomware gangs. In June 2026, SAP closed 15 vulnerabilities, while at the same time official npm packages were compromised in a supply chain attack to steal developer credentials. This underscores the historical relevance of SAP security updates in attacker playbooks.


Source: www.it-daily.net · Published July 15, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: