logo

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data

ID: b3716e2b-110c-5e62-9f55-01012bccac3e

STIX ID: report--b3716e2b-110c-5e62-9f55-01012bccac3e

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

Author: [email protected] (The Hacker News)

...
...

SAP released July 2026 security updates addressing multiple critical vulnerabilities — most notably CVE-2026-44747 (CVSS 9.9) in SAP NetWeaver AS ABAP that can cause out-of-bounds memory corruption, CVE-2026-27690 (CVSS 9.1) HTTP request/response smuggling in Approuter, and CVE-2026-44761 (CVSS 9.1) involving default/sample OAuth 2.0 credentials in Commerce Cloud. SAP and Onapsis recommend applying patches, and customers should audit and remove or reconfigure any sample OAuth clients retained in production; no evidence of active exploitation was reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.