The Bottom Line: SAP patches three critical vulnerabilities in NetWeaver, Approuter, and Commerce Cloud that enable memory corruption, unauthorized data access, and unauthorized logins.
SAP has patched three critical vulnerabilities in its NetWeaver, Approuter, and Commerce Cloud product lines. The gaps allow memory corruption, unauthorized data access, and logins using default credentials.
SAP has fixed three critical vulnerabilities in its NetWeaver, Approuter, and Commerce Cloud products in recent security updates. The vulnerabilities affect different attack scenarios and allow attackers to compromise systems at multiple levels.
The impacts vary depending on the affected component: while one vulnerability leads to memory corruption, others enable unauthorized data access or authentication using known default credentials. These combinations potentially allow complete control over affected systems.
CISOs should prioritize the corresponding SAP patches immediately and deploy them in their environments, especially if NetWeaver, Approuter, or Commerce Cloud are in productive use. Inventorying these components and their versions is the first step toward risk assessment and patch planning.
Source: www.security-insider.de · Published July 24, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification through Lumi News Pipeline v1.7.3.