Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Papyrus Ad Fraud Abuses Hidden WebViews to Fake User Engagement
August 7, 2026
Critical Flaws in Enterprise Java Platforms Let Attackers Execute Remote Code
August 7, 2026
Kimi K3 AI Model Sandbox Escape Exposes Sensitive Data
August 7, 2026
Home/CyberSecurity News/SAP Patches Critical NetWeaver Vulnerabilities
CyberSecurity News

SAP Patches Critical NetWeaver Vulnerabilities

Key Takeaways SAP released 15 new security notes on its June 2026 Patch Day, including four critical vulnerabilities. The most severe flaws include an XML Signature Wrapping vulnerability (CVSS 9.9)...

Marcus Rodriguez
Marcus Rodriguez
June 9, 2026 4 Min Read
53 0

Key Takeaways

  • SAP released 15 new security notes on its June 2026 Patch Day, including four critical vulnerabilities.
  • The most severe flaws include an XML Signature Wrapping vulnerability (CVSS 9.9) in NetWeaver AS ABAP and an unauthenticated memory corruption issue (CVSS 9.8) in the ABAP kernel.
  • Other critical vulnerabilities affect SAP Commerce Cloud, SAP Data Hub, and the NetWeaver Application Server Java Web Container.
  • SAP urges all customers to prioritize applying these patches to protect their systems from potential unauthorized access, data compromise, and system disruption.

SAP Addresses Critical NetWeaver Flaws in June 2026 Patch Release

On Tuesday, June 9, SAP issued its June 2026 Security Patch Day updates, comprising 15 new security notes. Among these, four are designated as critical, addressing severe vulnerabilities across key SAP products. Enterprises are strongly advised to implement these patches without delay to safeguard their SAP landscapes.

Table Of Content

  • Key Takeaways
  • SAP Addresses Critical NetWeaver Flaws in June 2026 Patch Release
  • Critical Vulnerabilities Detailed
  • High-Severity Patches
  • Medium and Low Severity Notes
  • What You Should Do

SAP has explicitly recommended that all customers access the SAP Support Portal and apply the necessary updates as a priority measure.

Critical Vulnerabilities Detailed

The most pressing security concern addressed in this cycle is CVE-2026-44748, an XML Signature Wrapping vulnerability in SAML Authentication. This flaw, rated with a CVSS score of 9.9, impacts SAP NetWeaver AS ABAP and ABAP Platform. An attacker with low authentication privileges could exploit this by obtaining a valid signed message, then altering and retransmitting XML documents. This could trick the system into accepting tampered identity information, leading to unauthorized access to sensitive user data and potential privilege escalation. The vulnerability affects a wide array of SAP_BASIS versions, specifically from 702 through 919.

Another critical issue, CVE-2026-27671 (CVSS 9.8), targets the Application Server ABAP kernel. This vulnerability introduces a memory corruption risk stemming from improper RFC protocol validation. Unlike the SAML flaw, this is an unauthenticated vulnerability, meaning an attacker could send specially crafted RFC requests without any valid credentials. Such an attack could exploit logical errors in memory management, leading to significant impacts on confidentiality, integrity, and availability. Various KRNL64NUC, KRNL64UC, and KERNEL versions are affected.

A third critical patch, CVE-2026-22732 (CVSS 9.1), addresses a Spring Security vulnerability present in SAP Commerce Cloud and SAP Data Hub. This flaw allows unauthenticated remote attackers to compromise confidentiality and integrity without requiring any user interaction.

Rounding out the critical vulnerabilities is CVE-2026-40128 (CVSS 9.0), a Directory Traversal flaw. This affects the SAP NetWeaver Application Server Java Web Container, specifically ENGINEAPI 7.50. A network-accessible attacker could exploit this to traverse directory structures, gaining access to sensitive resources and severely impacting confidentiality, integrity, and availability.

High-Severity Patches

Beyond the critical issues, SAP also released two high-priority notes. CVE-2026-29145 (CVSS 7.4) is a bundled patch addressing multiple Apache Tomcat vulnerabilities, including CVE-2025-66614 and CVE-2026-24734. These impact SAP Commerce Cloud (HY_COM 2205, COM_CLOUD 2211), allowing unauthenticated attackers to exploit weaknesses in the embedded Tomcat server.

CVE-2026-44751 (CVSS 7.1) resolves a Missing Authorization Check in SAP NetWeaver AS ABAP and ABAP Platform. This affects SAP_BASIS versions 700 through 816, where a low-privileged network attacker could achieve a high impact on integrity and partial availability disruption.

Medium and Low Severity Notes

Among the medium and low-severity patches, a notable vulnerability is the SQL Injection flaw in SAP S/4HANA (CVE-2026-44744, CVSS 6.5). This poses a data exposure risk, as authenticated, low-privileged attackers can query sensitive database content through specially crafted inputs across S4FND versions 102 through 109.

Additional patches include a Reflected XSS vulnerability in SAP NetWeaver’s JDBC Test Servlet (CVE-2026-44746) and an advisory related to Apache Log4j exposure (CVE-2025-68161) in SAP NetWeaver AS Java. The Log4j advisory highlights the ongoing risk posed by third-party library dependencies within SAP products, even as the initial critical Log4j vulnerabilities have been widely addressed.

What You Should Do

Organizations managing SAP environments should prioritize remediation efforts as follows:

  • Immediately address CVE-2026-44748: Apply the SAML XML Signature fix across all affected SAP_BASIS versions. As a temporary measure, SAML authentication can be disabled, though this may not cover all signed XML use cases.
  • Patch CVE-2026-27671 without delay: Update all affected SAP Kernel versions (7.22–9.19) to eliminate the unauthenticated RFC memory corruption vulnerability.
  • Prioritize CVE-2026-22732 and CVE-2026-40128: Update SAP Commerce Cloud, SAP Data Hub, and NetWeaver Java (ENGINEAPI 7.50) to mitigate the Spring Security and Directory Traversal flaws.
  • Apply CVE-2026-29145: Implement the Apache Tomcat bundle patch for SAP Commerce Cloud to resolve multiple embedded server vulnerabilities.
  • Schedule remaining medium/low notes: Integrate these into your standard monthly patch management cycle, with particular attention to the S/4HANA SQL injection and NetWeaver AS Java XSS fixes.

SAP Security Patch Day occurs on the second Tuesday of each month. Organizations are strongly encouraged to maintain a robust SAP patch management process and regularly monitor the SAP Security Notes portal for any urgent, out-of-band updates that may follow this cycle.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Threat Actors Phish Credentials Using Fake ChatGPT, Claude, DeepSeek Brands

Next Post

Critical LiteLLM RCE Vulnerability Under Active Exploitation

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OpenAI Expands GPT-3.5 Access With Unlimited Chats for All Users
August 7, 2026
SilverFox Hijacks Drivers to Disable Security Tools
August 7, 2026
Critical Rockwell Automation Flaw Exposes Water Systems to Cyberattacks
August 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us