SAP released patches in July 2026 against vulnerabilities that enable arbitrary code execution, SQL injection, cross-site scripting, file manipulation, information disclosure, and circumvention of security controls.
SAP patches three critical security vulnerabilities (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761) in NetWeaver, AppRouter and Commerce Cloud that enable memory corruption, DoS attacks and token theft.
The volume of monthly discovered security vulnerabilities has surged due to improved AI-powered vulnerability detection; security teams must adjust their response times and prioritize by risk rather than following the Exploitability Index alone.
The number of vulnerabilities patched monthly has become the new norm — AI-driven vulnerability scanning tools are dramatically accelerating discovery and forcing faster remediation processes.