Advertisementspot_img
HomeSecurity & JusticeSAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud

SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud

Enterprise software maker SAP on Tuesday announced the release of 20 new and updated security notes as part of its July 2026 security patch day.

The most severe of the resolved vulnerabilities is CVE-2026-44747 (CVSS score of 9.9), a memory corruption bug in NetWeaver Application Server ABAP.

Successful exploitation of the security defect could allow an attacker to access and modify data, and cause system unavailability, SAP security firm Onapsis explains.

SAP customers are strongly advised to apply the fresh patches to resolve the flaw, but can also “disable all ICF nodes with a specific property in transaction SICF” as a temporary workaround.

The second security note released on SAP’s July 2026 security patch day fixes a critical HTTP request smuggling issue in Approuter, tracked as CVE-2026-27690 (CVSS score of 9.1).

“The vulnerability affects SAP Approuter deployments in non-Cloud Foundry environments and allows an unauthenticated attacker to send a specially crafted HTTP request that leads to request-response desynchronization,” Onapsis says.

Advertisement. Scroll to continue reading.

Another critical-severity vulnerability was addressed in Commerce Cloud. Tracked as CVE-2026-44761 (CVSS score of 9.1), it is described as a hardcoded credential issue and could lead to unauthorized data access and modification.

The bug is related to sample configuration scripts that were previously provided in the SAP Help Portal for development and testing, and which configure OAuth2 clients with known credentials.

An unauthenticated attacker could abuse these credentials to obtain an access token that allows them to invoke specific APIs. This enables the attacker to read and tamper with system data.

“Exploitation requires that the customer execute the sample script and retain the resulting OAuth2 client in production without replacing the hardcoded secret. Customers who removed the sample client or replaced the secret with a strong, unique value are not affected,” Onapsis notes.

Older SAP documentation for Commerce Cloud did not warn customers against importing the default settings into production. The note addresses the lapse, but customers are advised to audit their production environments for the presence of the hardcoded credentials in sample OAuth2 clients.

On Tuesday, SAP also updated a security note addressing a critical NetWeaver vulnerability initially patched in June, to provide support for additional packages.

Additionally, the company released six security notes that address high-severity security defects across Integration Suite (Edge Integration Cell), SAProuter, NetWeaver Application Server Java (Configuration Wizard), Approuter, Commerce Cloud, and Change and Transport System Attach Tool (ctsattach).

The notes for Integration Suite and Commerce Cloud contain patches for multiple Apache Camel and Apache Tomcat security bugs.

The remaining new and updated notes released on SAP’s July 2026 security patch day address medium- and low-severity flaws across NetWeaver, S/4HANA, Fiori, CRM, and HANA Extended Application Services Classic Model.

Related: RabbitMQ Vulnerability Threatens Enterprise Systems

Related: Zimbra Patches Critical Code Execution Vulnerability

Related: SAP Patches Critical NetWeaver, Commerce Vulnerabilities

Related: SAP Patches Critical S/4HANA, Commerce Vulnerabilities


Source:

www.securityweek.com