SAP released June 2026 security updates for critical flaws in NetWeaver, Commerce Cloud, and Data Hub that could let attackers access sensitive data, crash systems, or bypass normal protections. The most severe issues are CVE-2026-44748, an XML Signature Wrapping flaw in NetWeaver AS ABAP and ABAP Platform SAML authentication rated 9.9; CVE-2026-27671, a 9.8 memory-corruption bug in the SAP kernel's RFC handling affecting NetWeaver and ABAP Platform; CVE-2026-22732, a 9.1 Spring Security header-handling issue affecting Commerce Cloud and Data Hub; and CVE-2026-40128, a 9.0 directory traversal flaw in NetWeaver Application Server Java reachable through crafted HTTP logon requests.
info@thehackernews.com (The Hacker News)
2026.07.14
93% relevant
This appears to be additional reporting on the same SAP security release cycle, adding focus on a CVSS 9.9 NetWeaver ABAP flaw that can expose or modify data in SAP NetWeaver deployments.
Sergiu Gatlan
2026.07.14
93% relevant
This article is an update on SAP's July 2026 security fixes for critical vulnerabilities in NetWeaver and Commerce Cloud, adding specific details on three patched critical flaws: CVE-2026-44747 in NetWeaver AS ABAP, CVE-2026-27690 in SAP Approuter, and CVE-2026-44761 in SAP Commerce Cloud, plus the overall count of 16 fixes in the July release.
Ionut Arghire
2026.07.14
91% relevant
This is the July 2026 SAP Security Patch Day follow-up to the same underlying SAP critical-patch event family, adding newly disclosed critical flaws in NetWeaver Application Server ABAP (CVE-2026-44747), Approuter (CVE-2026-27690), and Commerce Cloud (CVE-2026-44761), plus details on temporary mitigation and affected deployment conditions.
Bill Toulas
2026.06.09
98% relevant
This article is the same June 2026 SAP patch event and adds details on the full set of 15 fixes, highlighting four critical flaws including CVE-2026-44748 in NetWeaver, CVE-2026-27671 in ABAP, CVE-2026-22732 affecting Commerce Cloud and Data Hub, and CVE-2026-40128 in NetWeaver AS Java, plus two high-severity issues.
Ionut Arghire
2026.06.09
100% relevant
This article establishes a new tracked story around SAP's June 2026 Patch Day release and the specific critical CVEs affecting NetWeaver, Commerce Cloud, and Data Hub.