SAP warns of critical flaws in NetWeaver and Commerce Cloud
PatchNetWeaver Application Server ABAPApprouterOur summary
SAP has issued security updates addressing 16 vulnerabilities, including three critical flaws affecting its NetWeaver Application Server ABAP, Approuter, and Commerce Cloud. These include a memory corruption issue (CVE-2026-44747), an HTTP request smuggling flaw (CVE-2026-27690), and a vulnerability due to default credentials (CVE-2026-44761). While no active exploitation has been observed, these flaws could allow unauthorized access, data manipulation, or service disruption. Users are advised to apply the latest patches immediately.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.