SAP Patches Critical NetWeaver Vulnerabilities
Key Takeaways SAP released 15 new security notes on its June 2026 Patch Day, including four critical vulnerabilities. The most severe flaws include an XML Signature Wrapping vulnerability (CVSS 9.9)...
Key Takeaways
- SAP released 15 new security notes on its June 2026 Patch Day, including four critical vulnerabilities.
- The most severe flaws include an XML Signature Wrapping vulnerability (CVSS 9.9) in NetWeaver AS ABAP and an unauthenticated memory corruption issue (CVSS 9.8) in the ABAP kernel.
- Other critical vulnerabilities affect SAP Commerce Cloud, SAP Data Hub, and the NetWeaver Application Server Java Web Container.
- SAP urges all customers to prioritize applying these patches to protect their systems from potential unauthorized access, data compromise, and system disruption.
SAP Addresses Critical NetWeaver Flaws in June 2026 Patch Release
On Tuesday, June 9, SAP issued its June 2026 Security Patch Day updates, comprising 15 new security notes. Among these, four are designated as critical, addressing severe vulnerabilities across key SAP products. Enterprises are strongly advised to implement these patches without delay to safeguard their SAP landscapes.
Table Of Content
SAP has explicitly recommended that all customers access the SAP Support Portal and apply the necessary updates as a priority measure.
Critical Vulnerabilities Detailed
The most pressing security concern addressed in this cycle is CVE-2026-44748, an XML Signature Wrapping vulnerability in SAML Authentication. This flaw, rated with a CVSS score of 9.9, impacts SAP NetWeaver AS ABAP and ABAP Platform. An attacker with low authentication privileges could exploit this by obtaining a valid signed message, then altering and retransmitting XML documents. This could trick the system into accepting tampered identity information, leading to unauthorized access to sensitive user data and potential privilege escalation. The vulnerability affects a wide array of SAP_BASIS versions, specifically from 702 through 919.
Another critical issue, CVE-2026-27671 (CVSS 9.8), targets the Application Server ABAP kernel. This vulnerability introduces a memory corruption risk stemming from improper RFC protocol validation. Unlike the SAML flaw, this is an unauthenticated vulnerability, meaning an attacker could send specially crafted RFC requests without any valid credentials. Such an attack could exploit logical errors in memory management, leading to significant impacts on confidentiality, integrity, and availability. Various KRNL64NUC, KRNL64UC, and KERNEL versions are affected.
A third critical patch, CVE-2026-22732 (CVSS 9.1), addresses a Spring Security vulnerability present in SAP Commerce Cloud and SAP Data Hub. This flaw allows unauthenticated remote attackers to compromise confidentiality and integrity without requiring any user interaction.
Rounding out the critical vulnerabilities is CVE-2026-40128 (CVSS 9.0), a Directory Traversal flaw. This affects the SAP NetWeaver Application Server Java Web Container, specifically ENGINEAPI 7.50. A network-accessible attacker could exploit this to traverse directory structures, gaining access to sensitive resources and severely impacting confidentiality, integrity, and availability.
High-Severity Patches
Beyond the critical issues, SAP also released two high-priority notes. CVE-2026-29145 (CVSS 7.4) is a bundled patch addressing multiple Apache Tomcat vulnerabilities, including CVE-2025-66614 and CVE-2026-24734. These impact SAP Commerce Cloud (HY_COM 2205, COM_CLOUD 2211), allowing unauthenticated attackers to exploit weaknesses in the embedded Tomcat server.
CVE-2026-44751 (CVSS 7.1) resolves a Missing Authorization Check in SAP NetWeaver AS ABAP and ABAP Platform. This affects SAP_BASIS versions 700 through 816, where a low-privileged network attacker could achieve a high impact on integrity and partial availability disruption.
Medium and Low Severity Notes
Among the medium and low-severity patches, a notable vulnerability is the SQL Injection flaw in SAP S/4HANA (CVE-2026-44744, CVSS 6.5). This poses a data exposure risk, as authenticated, low-privileged attackers can query sensitive database content through specially crafted inputs across S4FND versions 102 through 109.
Additional patches include a Reflected XSS vulnerability in SAP NetWeaver’s JDBC Test Servlet (CVE-2026-44746) and an advisory related to Apache Log4j exposure (CVE-2025-68161) in SAP NetWeaver AS Java. The Log4j advisory highlights the ongoing risk posed by third-party library dependencies within SAP products, even as the initial critical Log4j vulnerabilities have been widely addressed.
What You Should Do
Organizations managing SAP environments should prioritize remediation efforts as follows:
- Immediately address CVE-2026-44748: Apply the SAML XML Signature fix across all affected SAP_BASIS versions. As a temporary measure, SAML authentication can be disabled, though this may not cover all signed XML use cases.
- Patch CVE-2026-27671 without delay: Update all affected SAP Kernel versions (7.22–9.19) to eliminate the unauthenticated RFC memory corruption vulnerability.
- Prioritize CVE-2026-22732 and CVE-2026-40128: Update SAP Commerce Cloud, SAP Data Hub, and NetWeaver Java (ENGINEAPI 7.50) to mitigate the Spring Security and Directory Traversal flaws.
- Apply CVE-2026-29145: Implement the Apache Tomcat bundle patch for SAP Commerce Cloud to resolve multiple embedded server vulnerabilities.
- Schedule remaining medium/low notes: Integrate these into your standard monthly patch management cycle, with particular attention to the S/4HANA SQL injection and NetWeaver AS Java XSS fixes.
SAP Security Patch Day occurs on the second Tuesday of each month. Organizations are strongly encouraged to maintain a robust SAP patch management process and regularly monitor the SAP Security Notes portal for any urgent, out-of-band updates that may follow this cycle.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.