Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

SAP fixes critical flaws in NetWeaver and Commerce Cloud

0
Critical
Vulnerabilityrce
Published: Tue Jun 09 2026 (06/09/2026, 19:36:27 UTC)
Source: Bleeping Computer

Description

SAP released its June 2026 Security Patch package addressing 15 vulnerabilities, including four critical flaws in SAP NetWeaver and SAP Commerce Cloud. The critical issues include an XML Signature Wrapping vulnerability enabling authentication bypass in SAML environments, a memory corruption flaw exploitable without authentication, a Spring Security-related vulnerability affecting Commerce Cloud, and a directory traversal flaw in NetWeaver Application Server Java. These vulnerabilities could lead to unauthorized access, system disruption, or memory corruption. SAP customers are advised to prioritize patching these critical issues. Detailed mitigation guidance is available only to SAP customers through the SAP security portal.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/09/2026, 19:40:56 UTC

Technical Analysis

The June 2026 SAP Security Patch package fixes 15 vulnerabilities, with four critical-severity flaws impacting SAP NetWeaver and SAP Commerce Cloud. CVE-2026-44748 (CVSS 9.9) is an XML Signature Wrapping vulnerability in NetWeaver AS ABAP and ABAP Platform that may allow authentication bypass in SAML-based environments by accepting tampered identity information. CVE-2026-27671 (CVSS 9.8) is a memory corruption vulnerability in NetWeaver/ABAP Platform Application Server ABAP exploitable without authentication via crafted RFC requests. CVE-2026-22732 (CVSS 9.1) affects SAP Commerce Cloud and SAP Data Hub through a Spring Security-related issue. CVE-2026-40128 (CVSS 9.0) is a directory traversal vulnerability in NetWeaver Application Server Java's Web Container. Additional high-severity and other vulnerabilities were also addressed. SAP restricts detailed mitigation information to customers with security portal access.

Potential Impact

The critical vulnerabilities could allow attackers to bypass authentication mechanisms, gain unauthorized access to sensitive user data, cause memory corruption without authentication, and perform directory traversal attacks. These impacts could lead to unauthorized system access, data exposure, and potential disruption of normal business operations in enterprise environments using SAP NetWeaver and Commerce Cloud platforms.

Mitigation Recommendations

SAP has released official patches for these vulnerabilities as part of its June 2026 Security Patch package. Organizations using affected SAP products should prioritize applying these patches promptly. Detailed remediation instructions and workarounds are available exclusively to SAP customers through the SAP security portal. Patch status is confirmed as fixed by SAP's official security bulletin.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/sap-fixes-critical-flaws-in-netweaver-and-commerce-cloud/","fetched":true,"fetchedAt":"2026-06-09T19:40:46.366Z","wordCount":698}

Threat ID: 6a286c3e8dd33fbd85742bb2

Added to database: 6/9/2026, 7:40:46 PM

Last enriched: 6/9/2026, 7:40:56 PM

Last updated: 6/9/2026, 10:27:34 PM

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses