SAP fixes critical flaws in NetWeaver and Commerce Cloud
SAP released its June 2026 Security Patch package addressing 15 vulnerabilities, including four critical flaws in SAP NetWeaver and SAP Commerce Cloud. The critical issues include an XML Signature Wrapping vulnerability enabling authentication bypass in SAML environments, a memory corruption flaw exploitable without authentication, a Spring Security-related vulnerability affecting Commerce Cloud, and a directory traversal flaw in NetWeaver Application Server Java. These vulnerabilities could lead to unauthorized access, system disruption, or memory corruption. SAP customers are advised to prioritize patching these critical issues. Detailed mitigation guidance is available only to SAP customers through the SAP security portal.
AI Analysis
Technical Summary
The June 2026 SAP Security Patch package fixes 15 vulnerabilities, with four critical-severity flaws impacting SAP NetWeaver and SAP Commerce Cloud. CVE-2026-44748 (CVSS 9.9) is an XML Signature Wrapping vulnerability in NetWeaver AS ABAP and ABAP Platform that may allow authentication bypass in SAML-based environments by accepting tampered identity information. CVE-2026-27671 (CVSS 9.8) is a memory corruption vulnerability in NetWeaver/ABAP Platform Application Server ABAP exploitable without authentication via crafted RFC requests. CVE-2026-22732 (CVSS 9.1) affects SAP Commerce Cloud and SAP Data Hub through a Spring Security-related issue. CVE-2026-40128 (CVSS 9.0) is a directory traversal vulnerability in NetWeaver Application Server Java's Web Container. Additional high-severity and other vulnerabilities were also addressed. SAP restricts detailed mitigation information to customers with security portal access.
Potential Impact
The critical vulnerabilities could allow attackers to bypass authentication mechanisms, gain unauthorized access to sensitive user data, cause memory corruption without authentication, and perform directory traversal attacks. These impacts could lead to unauthorized system access, data exposure, and potential disruption of normal business operations in enterprise environments using SAP NetWeaver and Commerce Cloud platforms.
Mitigation Recommendations
SAP has released official patches for these vulnerabilities as part of its June 2026 Security Patch package. Organizations using affected SAP products should prioritize applying these patches promptly. Detailed remediation instructions and workarounds are available exclusively to SAP customers through the SAP security portal. Patch status is confirmed as fixed by SAP's official security bulletin.
SAP fixes critical flaws in NetWeaver and Commerce Cloud
Description
SAP released its June 2026 Security Patch package addressing 15 vulnerabilities, including four critical flaws in SAP NetWeaver and SAP Commerce Cloud. The critical issues include an XML Signature Wrapping vulnerability enabling authentication bypass in SAML environments, a memory corruption flaw exploitable without authentication, a Spring Security-related vulnerability affecting Commerce Cloud, and a directory traversal flaw in NetWeaver Application Server Java. These vulnerabilities could lead to unauthorized access, system disruption, or memory corruption. SAP customers are advised to prioritize patching these critical issues. Detailed mitigation guidance is available only to SAP customers through the SAP security portal.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The June 2026 SAP Security Patch package fixes 15 vulnerabilities, with four critical-severity flaws impacting SAP NetWeaver and SAP Commerce Cloud. CVE-2026-44748 (CVSS 9.9) is an XML Signature Wrapping vulnerability in NetWeaver AS ABAP and ABAP Platform that may allow authentication bypass in SAML-based environments by accepting tampered identity information. CVE-2026-27671 (CVSS 9.8) is a memory corruption vulnerability in NetWeaver/ABAP Platform Application Server ABAP exploitable without authentication via crafted RFC requests. CVE-2026-22732 (CVSS 9.1) affects SAP Commerce Cloud and SAP Data Hub through a Spring Security-related issue. CVE-2026-40128 (CVSS 9.0) is a directory traversal vulnerability in NetWeaver Application Server Java's Web Container. Additional high-severity and other vulnerabilities were also addressed. SAP restricts detailed mitigation information to customers with security portal access.
Potential Impact
The critical vulnerabilities could allow attackers to bypass authentication mechanisms, gain unauthorized access to sensitive user data, cause memory corruption without authentication, and perform directory traversal attacks. These impacts could lead to unauthorized system access, data exposure, and potential disruption of normal business operations in enterprise environments using SAP NetWeaver and Commerce Cloud platforms.
Mitigation Recommendations
SAP has released official patches for these vulnerabilities as part of its June 2026 Security Patch package. Organizations using affected SAP products should prioritize applying these patches promptly. Detailed remediation instructions and workarounds are available exclusively to SAP customers through the SAP security portal. Patch status is confirmed as fixed by SAP's official security bulletin.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/sap-fixes-critical-flaws-in-netweaver-and-commerce-cloud/","fetched":true,"fetchedAt":"2026-06-09T19:40:46.366Z","wordCount":698}
Threat ID: 6a286c3e8dd33fbd85742bb2
Added to database: 6/9/2026, 7:40:46 PM
Last enriched: 6/9/2026, 7:40:56 PM
Last updated: 6/9/2026, 10:27:34 PM
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.