Overview
- SAP published its July 2026 security notes on July 14, releasing 19 new and updated advisories that cover critical, high, medium and low severity flaws across its core products.
- A critical NetWeaver ABAP memory corruption flaw (CVE-2026-44747, CVSS 9.9) can let an authenticated attacker read or modify data or cause service outages and SAP recommends installing the kernel patch or disabling specific ICF nodes in transaction SICF as a temporary workaround.
- A critical HTTP request smuggling bug in Approuter (CVE-2026-27690, CVSS 9.1) affects non-Cloud Foundry deployments and allows an unauthenticated attacker to send crafted HTTP requests that desynchronize request and response handling, exposing user data or causing denial of service.
- A Commerce Cloud issue (CVE-2026-44761, CVSS 9.1) stems from sample configuration scripts that create OAuth2 clients with hardcoded credentials and could let an unauthenticated attacker obtain tokens to read or change data, so customers should audit and remove or rotate any sample clients kept in production.
- SAP says it has found no evidence these flaws were exploited, but prior SAP supply‑chain compromises and CISA listings of SAP bugs raise the risk to customers and make immediate patching, auditing, and the vendor's mitigation steps a priority to reduce the chance of data theft or ransomware follow‑on attacks.