SAP fixes critical flaws in NetWeaver and Commerce Cloud
ID: 503cc65c-eee8-5420-8c4d-5806b9705559
STIX ID: report--503cc65c-eee8-5420-8c4d-5806b9705559
Feed Name: Bleeping Computer
SAP's June 2026 security bulletin fixes 15 vulnerabilities including four critical issues impacting NetWeaver, ABAP Platform and Commerce Cloud — notably an XML Signature Wrapping SAML issue (CVE-2026-44748, CVSS 9.9), an unauthenticated memory corruption via crafted RFC requests (CVE-2026-27671, CVSS 9.8), a Spring Security flaw in Commerce Cloud (CVE-2026-22732, CVSS 9.1), and a directory traversal in AS Java (CVE-2026-40128, CVSS 9.0); organizations using these products should prioritize patching the highest-severity flaws.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
