CVE Tools

SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud

SecurityWeekBy Ionut Arghire

PatchNetWeaver Application Server ABAPApprouter

Our summary

SAP has issued urgent security updates to fix several high-risk vulnerabilities affecting its core enterprise platforms. Among the most severe is CVE-2026-44747, a memory corruption flaw in NetWeaver Application Server ABAP with a CVSS score of 9.9. Attackers could exploit this to manipulate data or disrupt services. A separate HTTP request smuggling vulnerability (CVE-2026-27690) impacts Approuter, allowing unauthenticated attackers to send malicious requests. Additionally, a hardcoded credential issue in Commerce Cloud (CVE-2026-44761) could enable unauthorized access if default configurations are left unchanged. SAP urges users to apply the latest patches immediately.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store