• 2 min read
SAP fixes 3 critical bugs in NetWeaver and Commerce Cloud
SAP’s July 2026 security update patches 16 flaws, including three critical issues in NetWeaver, Approuter, and Commerce Cloud.

Image: BleepingComputer
SAP has patched 16 vulnerabilities across multiple products in its July 2026 security updates, including three critical flaws affecting NetWeaver, Commerce Cloud, and Approuter.
The most serious issues include CVE-2026-44747, a memory corruption bug in SAP NetWeaver Application Server ABAP (AS ABAP) caused by an out-of-bounds write. SAP said an authenticated attacker could exploit memory management errors to cause unauthorized data access, data modification, or system unavailability.
“SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability.”
SAP also fixed CVE-2026-27690, an HTTP Request Smuggling vulnerability in SAP Approuter, the company’s Node.js-based middleware library for cloud apps on SAP Business Technology Platform (SAP BTP). According to SAP, unauthenticated attackers could abuse specially crafted HTTP requests to access user responses and launch denial-of-service attacks.

Recommended reading
23M Paidwork accounts reportedly exposed online
The third critical flaw, CVE-2026-44761, affects SAP Commerce Cloud. It stems from default credentials that could let attackers obtain valid access tokens and read or modify data through certain APIs.
Beyond the three critical bugs, SAP’s advisory includes fixes for six high-severity, seven medium-severity, and one low-severity vulnerability. The list spans DLL hijacking, open redirect, missing authorization checks, remote code execution, cross-site scripting (XSS), path traversal, SQL injection, denial-of-service, information disclosure, and security misconfigurations.
SAP said it has not found evidence that the newly patched flaws have been exploited. Even so, the company has been a frequent target: CISA has added 14 SAP security flaws to its Known Exploited Vulnerabilities catalog since November 2021, including two used by ransomware gangs.
The update follows SAP’s June 2026 patch package, which fixed 15 vulnerabilities. That same month, attackers also compromised multiple official SAP npm packages in a supply chain attack designed to steal credentials from developers' systems.
SAP reported total revenue of more than €36 billion in fiscal year 2025 and says it serves 99 of the 100 largest companies worldwide.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via BleepingComputer


