SAP security updates released for July 2026 fix 16 vulnerabilities across several enterprise products. The update includes three critical flaws affecting NetWeaver, Commerce Cloud, and AppRouter, along with multiple high-severity security issues.
Although SAP has not seen any active attacks targeting these vulnerabilities, organizations are encouraged to install the updates as soon as possible.
Critical NetWeaver Flaw Could Lead to Memory Corruption
The most severe issue fixed this month is CVE-2026-44747, a memory corruption vulnerability in SAP NetWeaver Application Server ABAP (AS ABAP).
The flaw results from an out-of-bounds write weakness in the platform’s memory management. An authenticated attacker could exploit the vulnerability to corrupt memory, potentially gaining unauthorized access to sensitive data, modifying information, or causing the application to become unavailable.
Because the vulnerability affects confidentiality, integrity, and availability, SAP assigned it a critical severity rating.
SAP AppRouter Vulnerability Enables HTTP Request Smuggling
SAP also addressed CVE-2026-27690, a critical HTTP Request Smuggling vulnerability in SAP AppRouter.
AppRouter is a Node.js-based middleware library used by cloud applications running on the SAP Business Technology Platform.
An attacker does not need authentication to exploit the flaw. By sending specially crafted HTTP requests, they could access responses intended for other users or trigger denial-of-service attacks against vulnerable systems.
Default Credentials Exposed Commerce Cloud Systems
The third critical vulnerability, CVE-2026-44761, affects SAP Commerce Cloud.
The issue stems from default credentials that could allow attackers to obtain valid access tokens. Once authenticated, they could read or modify data through affected APIs.
Removing default credentials and applying SAP’s security update are essential to protecting exposed environments.
Six High-Severity Vulnerabilities Also Resolved
Beyond the three critical flaws, SAP’s July security release fixes six high-severity vulnerabilities, seven medium-severity issues, and one low-severity flaw.
The update addresses several common attack vectors, including:
- Remote code execution
- DLL hijacking
- SQL injection
- Cross-site scripting (XSS)
- Path traversal
- Open redirects
- Missing authorization checks
- Information disclosure
- Denial-of-service
- Security misconfigurations
Applying the full security package helps reduce exposure across multiple SAP products.
No Active Exploitation Reported
SAP says it has not found evidence that attackers are actively exploiting the vulnerabilities fixed in the July 2026 release.
However, the company’s software has been a frequent target in recent years. Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 14 SAP vulnerabilities to its Known Exploited Vulnerabilities catalog. Two of those flaws were later used by ransomware operators.
Last month, SAP released fixes for 15 vulnerabilities in its June 2026 security update. More recently, the company also responded to a supply chain attack that compromised several official SAP npm packages in an attempt to steal developer credentials.
Given SAP’s widespread use among the world’s largest enterprises, organizations should prioritize deploying the latest security updates to reduce the risk of future attacks.


0 responses to “SAP Security Updates Fix 16 Vulnerabilities Including Three Critical Flaws”