logo

SAP fixes critical flaws in NetWeaver and Commerce Cloud

ID: 503cc65c-eee8-5420-8c4d-5806b9705559

STIX ID: report--503cc65c-eee8-5420-8c4d-5806b9705559

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Bill Toulas

...
...

SAP's June 2026 security bulletin fixes 15 vulnerabilities including four critical issues impacting NetWeaver, ABAP Platform and Commerce Cloud — notably an XML Signature Wrapping SAML issue (CVE-2026-44748, CVSS 9.9), an unauthenticated memory corruption via crafted RFC requests (CVE-2026-27671, CVSS 9.8), a Spring Security flaw in Commerce Cloud (CVE-2026-22732, CVSS 9.1), and a directory traversal in AS Java (CVE-2026-40128, CVSS 9.0); organizations using these products should prioritize patching the highest-severity flaws.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.