• News/
  • bleepingcomputer-20260714114221

SAP warns of critical flaws in NetWeaver and Commerce Cloud

BleepingComputer
·
Sergiu Gatlan
·
Published Jul 14, 2026
·
Updated

SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. The first critical issue patched this month is a memory corruption security issue (tracked as CVE-2026-44747) stemming from an out-of-bounds write weakness in the NetWeaver Application Server ABAP (AS ABAP), the runtime environment, application server, and development platform for core SAP enterprise software. "SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability," SAP says. "This has high impact on confidentiality, integrity, and availability of the application." The second one (CVE-2026-27690) is an HTTP Request Smuggling vulnerability in SAP Approuter, a Node.js-based middleware library for cloud-based apps deployed on the company's Business Technology Platform (SAP BTP). Unauthenticated attackers can exploit this flaw via specially crafted HTTP requests to access user responses and trigger denial-of-service attacks on the targeted system. The third critical flaw addressed today (tracked as CVE-2026-44761) was found in the SAP Commerce Cloud enterprise e-commerce platform and stems from default credentials that enable attackers to get valid access tokens and read or modify data via certain APIs. SAP's July 2026 advisor...

Read full article

Affected Software

3 affected components
SAP NetWeaver Application Server ABAP (AS ABAP)
SAP Approuter
SAP Commerce Cloud
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What products are affected by the vulnerabilities addressed in the SAP security updates?

The affected products include SAP NetWeaver, SAP Commerce Cloud, and SAP AppRouter.

2

How many vulnerabilities did SAP address in its July 2026 security updates?

SAP addressed a total of 16 vulnerabilities in its July 2026 security updates.

3

What is the nature of the critical vulnerabilities identified in SAP products?

The critical vulnerabilities include memory corruption issues and other security flaws.

4

What is the CVE designation for the first critical issue patched by SAP this month?

The first critical issue patched is tracked as CVE-2026-44747.

5

What date were the security updates for the SAP products published?

The security updates for the SAP products were published on July 14, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203