logo

SAP Security Patch Day: Critical Security Vulnerabilities Remediated

ID: 973af0a0-4b1d-5f7d-830d-04e274ab795e

STIX ID: report--973af0a0-4b1d-5f7d-830d-04e274ab795e

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Do Son

...
...

**Executive summary:** The June 2026 SAP Security Patch Day publishes fixes for multiple critical vulnerabilities—most notably CVE-2026-44748 (SAML XML signature wrapping, CVSS 9.9), CVE-2026-27671 (ABAP kernel memory corruption via crafted RFC), CVE-2026-40128 (Java Web Container directory traversal), and CVE-2026-22732 (Spring Security header-lazy writing enabling connection hijacking). The advisory recommends immediate deployment of patches and system audits to prevent unauthorized access, service disruption, and potential exploitation of enterprise SAP deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.