CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

SAP Patches Critical CVSS 9.9 NetWeaver ABAP Flaw Allowing Data Exposure or Modification

July 14, 2026

SAP has released its July 2026 security updates, addressing multiple vulnerabilities including a critical out-of-bounds write flaw in SAP NetWeaver Application Server ABAP, tracked as CVE-2026-44747 with a CVSS score of 9.9. This vulnerability allows an authenticated attacker to exploit logical errors in memory management, leading to memory corruption that could result in unauthorized data access, modification, or system unavailability.

Onapsis, an SAP security firm, noted that a temporary workaround involves disabling all ICF nodes with a specific property in transaction SICF, but this may block opening transactions in SAP GUI for HTML, making patching the ABAP Kernel version the recommended course of action.

Two other critical vulnerabilities were also patched: CVE-2026-27690 (CVSS 9.1) is an HTTP request/response smuggling flaw in SAP Approuter deployments in non-Cloud Foundry environments, enabling an unauthenticated attacker to cause request-response desynchronization, exposing user responses and triggering denial-of-service attacks. CVE-2026-44761 (CVSS 9.1) involves the use of default credentials in SAP Commerce Cloud, where a sample OAuth 2.0 client with publicly documented credentials from SAP Help Portal documentation could be exploited by an unauthenticated attacker to obtain a valid access token and invoke APIs to read and modify data.

Onapsis highlighted that the default credentials issue stems from sample configuration scripts originally intended for development and testing, which were not explicitly warned against importing into production. Customers who removed the sample client or replaced the secret are not affected. While no active exploitation has been observed, SAP urges customers to apply updates promptly.

CVEs: CVE-2026-44747, CVE-2026-27690, CVE-2026-44761

Companies: SAP, Onapsis

Products: SAP NetWeaver Application Server ABAP, SAP Approuter, SAP Commerce Cloud, SAP Help Portal