INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw
| 2026-07-14 18:17 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The SAP NetWeaver Application Server ABAP vulnerability has been identified as a critical flaw that could expose or modify data, with a CVSS score of 9.9. This out-of-bounds write flaw allows an authenticated attacker to leverage logical errors in memory management to cause unauthorized access, modification, or system unavailability. The vulnerability is currently being patched by SAP and its partners, including the National Vulnerability Database (NVD) which has added it to their Known Exploited Vulnerabilities catalog since November 2023.
Technical Mitigations AI-generated
* Disable ICF nodes with specific property: As a temporary workaround, customers should disable all ICF (Intrusion Countermeasures Framework) nodes with a specific property in transaction SICF. This will prevent an attacker from exploiting the vulnerability.
* Update ABAP Kernel version: SAP recommends installing the patching ABAP Kernel version to address the memory corruption security issue (CVE-2026-44747).
* Remove or replace default OAuth 2.0 client credentials: Customers should audit their production environments for the presence of the affected sample OAuth 2.0 client and remove it if present, or replace the hard-coded secret with a strong, unique value.
* Monitor for exploitation attempts: Keep an eye on your system's logs and monitoring tools to detect any unauthorized access attempts using the vulnerable credentials.
* Implement secure configuration practices: Ensure that all sample configurations scripts are properly secured by removing or replacing default settings, and use secure coding practices when developing new applications.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
No•••••.js
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-27690CVE-2026-27690
CVE-2026-44747CVE-2026-44747
CVE-2026-44761CVE-2026-44761
Target & Sectors
DACH
DACH
technologytechnology
Incident Timeline
November 2021
Threat actors used a SAP Patches CVSS 9.9 NetWeaver ABAP Flaw to target the company in November 2021.
Click on any entity below to view its context and source!
general_metric
14 Jul
While the company has yet to find evidence that the vulnerabilities patched today have been exploited in attacks, CISA
has added 14 SAP security flaws
to its Known Exploited Vulnerabilities catalog since November 2021, including two that were abused by ransomware gangs.
tactic
Ransomware
While the company has yet to find evidence that the vulnerabilities patched today have been exploited in attacks, CISA
has added 14 SAP security flaws
to its Known Exploited Vulnerabilities catalog since November 2021, including two that were abused by ransomware gangs.
attribution
Known Exploited
While the company has yet to find evidence that the vulnerabilities patched today have been exploited in attacks, CISA
has added 14 SAP security flaws
to its Known Exploited Vulnerabilities catalog since November 2021, including two that were abused by ransomware gangs.
tactic
T1588.006 - Vulnerabilities
While the company has yet to find evidence that the vulnerabilities patched today have been exploited in attacks, CISA
has added 14 SAP security flaws
to its Known Exploited Vulnerabilities catalog since November 2021, including two that were abused by ransomware gangs.
fiscal year 2025
Threat actors exploited a SAP Patches CVSS 9.9 NetWeaver ABAP Flaw that could expose or modify data on affected servers in Germany and target companies with revenues exceeding €36 billion.
Click on any entity below to view its context and source!
target_region
Germany
The German multinational software corporation has reported total revenues exceeding €36 billion in fiscal year 2025 and servers 99 of the 100 largest companies worldwide.
financial
€36 revenues
The German multinational software corporation has reported total revenues exceeding €36 billion in fiscal year 2025 and servers 99 of the 100 largest companies worldwide.
general_metric
99 year
The German multinational software corporation has reported total revenues exceeding €36 billion in fiscal year 2025 and servers 99 of the 100 largest companies worldwide.
general_metric
100 largest companies
The German multinational software corporation has reported total revenues exceeding €36 billion in fiscal year 2025 and servers 99 of the 100 largest companies worldwide.
June 2026
Threat actors exploited a SAP Patches CVSS 9.9 NetWeaver ABAP Flaw in the June 2026 Security Patch package to compromise multiple official SAP npm packages, aiming at stealing credentials from developers' systems.
Click on any entity below to view its context and source!
general_metric
15 vulnerabilities
Most recently, SAP
fixed 15 vulnerabilities
as part of its June 2026 Security Patch package, and attackers compromised multiple official SAP npm packages
in a supply chain attack
aimed at stealing credentials from developers' systems.
Jul 14, 2026
Threat actors exploited a CVSS 9.9 NetWeaver ABAP flaw in SAP Patches to gain unauthorized access and potentially expose or modify sensitive data on affected systems.
2026/07/14
Threat actors used default credentials to gain access tokens and read or modify data via certain APIs in the SAP Commerce Cloud enterprise e-commerce platform.
Click on any entity below to view its context and source!
general_metric
14 Jul
While the company has yet to find evidence that the vulnerabilities patched today have been exploited in attacks, CISA
has added 14 SAP security flaws
to its Known Exploited Vulnerabilities catalog since November 2021, including two that were abused by ransomware gangs.
tactic
Ransomware
While the company has yet to find evidence that the vulnerabilities patched today have been exploited in attacks, CISA
has added 14 SAP security flaws
to its Known Exploited Vulnerabilities catalog since November 2021, including two that were abused by ransomware gangs.
attribution
Known Exploited
While the company has yet to find evidence that the vulnerabilities patched today have been exploited in attacks, CISA
has added 14 SAP security flaws
to its Known Exploited Vulnerabilities catalog since November 2021, including two that were abused by ransomware gangs.
tactic
T1588.006 - Vulnerabilities
While the company has yet to find evidence that the vulnerabilities patched today have been exploited in attacks, CISA
has added 14 SAP security flaws
to its Known Exploited Vulnerabilities catalog since November 2021, including two that were abused by ransomware gangs.
vulnerability
CVE-2026-44761
The third critical flaw addressed today (tracked as
CVE-2026-44761
) was found in the SAP Commerce Cloud enterprise e-commerce platform and stems from default credentials that enable attackers to get valid access tokens and read or modify data via certain APIs.
2026/07/14
Threat actors used an HTTP Request Smuggling vulnerability in SAP Approuter to target the NetWeaver Application Server ABAP.
Click on any entity below to view its context and source!
organisation
SAP Patches
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data.
organisation
Modify Data
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data.
organisation
the NetWeaver Application
The first critical issue patched this month is a memory corruption security issue (tracked as
CVE-2026-44747
) stemming from an out-of-bounds write weakness in the NetWeaver Application Server ABAP (AS ABAP), the runtime environment, application server, and development platform for core SAP enterprise software.
organisation
Business Technology Platform
The second one (CVE-2026-27690) is an HTTP Request Smuggling vulnerability in SAP Approuter, a Node.js-based middleware library for cloud-based apps deployed on the company's Business Technology Platform (SAP BTP).
organisation
SAP
SAP warns of critical flaws in NetWeaver and Commerce Cloud.
organisation
NetWeaver
SAP warns of critical flaws in NetWeaver and Commerce Cloud.
organisation
SAP NetWeaver Application
"SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability," SAP says.
organisation
Unauthenticated
Unauthenticated attackers can exploit this flaw via specially crafted HTTP requests to access user responses and trigger denial-of-service attacks on the targeted system.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
July 2026
SAP has rolled out updates to address multiple vulnerabilities, including a critical flaw in SAP NetWeaver Application Server ABAP that allows an authenticated attacker to leverage logical errors in memory management.
Click on any entity below to view its context and source!
organisation
SAP
Ravie Lakshmanan
Jul 14, 2026
Enterprise Security / Vulnerability
SAP has rolled out updates to address
multiple vulnerabilities
as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP.
organisation
SAP NetWeaver Application
Ravie Lakshmanan
Jul 14, 2026
Enterprise Security / Vulnerability
SAP has rolled out updates to address
multiple vulnerabilities
as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP.
tactic
T1584.004 - Server
Ravie Lakshmanan
Jul 14, 2026
Enterprise Security / Vulnerability
SAP has rolled out updates to address
multiple vulnerabilities
as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP.
general_metric
14 Jul
Ravie Lakshmanan
Jul 14, 2026
Enterprise Security / Vulnerability
SAP has rolled out updates to address
multiple vulnerabilities
as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP.
tactic
Remote Code Execution
SAP's
July 2026 advisory
also lists fixes for six high-severity flaws, seven medium-severity ones, and one low-severity vulnerability, including DLL hijacking, open redirect, missing authorization checks, remote code execution, cross-site scripting (XSS), path traversal, SQL injection, denial-of-service, information disclosure, and security misconfigurations.
organisation
DLL
SAP's
July 2026 advisory
also lists fixes for six high-severity flaws, seven medium-severity ones, and one low-severity vulnerability, including DLL hijacking, open redirect, missing authorization checks, remote code execution, cross-site scripting (XSS), path traversal, SQL injection, denial-of-service, information disclosure, and security misconfigurations.
organisation
SQL
SAP's
July 2026 advisory
also lists fixes for six high-severity flaws, seven medium-severity ones, and one low-severity vulnerability, including DLL hijacking, open redirect, missing authorization checks, remote code execution, cross-site scripting (XSS), path traversal, SQL injection, denial-of-service, information disclosure, and security misconfigurations.
organisation
AppRouter
SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter.
general_metric
16 vulnerabilities
SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter.
organisation
CVE-2026-27690
"Since the workaround will disable opening transactions in SAP GUI for HTML, it is not an option for all customers and it is strongly recommended to install the patching ABAP Kernel version."
Also addressed by SAP are two other critical vulnerabilities -
CVE-2026-27690
(CVSS score: 9.1) -
infrastructure
9.1
"Since the workaround will disable opening transactions in SAP GUI for HTML, it is not an option for all customers and it is strongly recommended to install the patching ABAP Kernel version."
Also addressed by SAP are two other critical vulnerabilities -
CVE-2026-27690
(CVSS score: 9.1) -
organisation
SAP GUI
"Since the workaround will disable opening transactions in SAP GUI for HTML, it is not an option for all customers and it is strongly recommended to install the patching ABAP Kernel version."
Also addressed by SAP are two other critical vulnerabilities -
CVE-2026-27690
(CVSS score: 9.1) -
organisation
HTML
"Since the workaround will disable opening transactions in SAP GUI for HTML, it is not an option for all customers and it is strongly recommended to install the patching ABAP Kernel version."
Also addressed by SAP are two other critical vulnerabilities -
CVE-2026-27690
(CVSS score: 9.1) -
organisation
Kernel
"Since the workaround will disable opening transactions in SAP GUI for HTML, it is not an option for all customers and it is strongly recommended to install the patching ABAP Kernel version."
Also addressed by SAP are two other critical vulnerabilities -
CVE-2026-27690
(CVSS score: 9.1) -
organisation
CVE-2026
CVE-2026-44761
(CVSS score: 9.1) -
organisation
the NIST National Vulnerability Database
"If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data," according to a description of CVE-2026-44761 in the NIST National Vulnerability Database (NVD).
organisation
NVD
"If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data," according to a description of CVE-2026-44761 in the NIST National Vulnerability Database (NVD).
organisation
SAP Approuter
An HTTP request/response smuggling flaw in SAP Approuter deployments in non-Cloud Foundry environments that allows an unauthenticated attacker to send a specially crafted HTTP request that leads to request-response desynchronization and results in the exposure of user responses and triggers denial-of-service (DoS) attacks.
organisation
DoS
An HTTP request/response smuggling flaw in SAP Approuter deployments in non-Cloud Foundry environments that allows an unauthenticated attacker to send a specially crafted HTTP request that leads to request-response desynchronization and results in the exposure of user responses and triggers denial-of-service (DoS) attacks.
organisation
SAP Commerce Cloud
A use of default credentials flaw in SAP Commerce Cloud that could retain a sample OAuth 2.0 client with publicly documented sample credentials originating from a sample configuration provided in SAP Help Portal documentation.
organisation
SAP Help Portal
A use of default credentials flaw in SAP Commerce Cloud that could retain a sample OAuth 2.0 client with publicly documented sample credentials originating from a sample configuration provided in SAP Help Portal documentation.
victims
2.0 client
A use of default credentials flaw in SAP Commerce Cloud that could retain a sample OAuth 2.0 client with publicly documented sample credentials originating from a sample configuration provided in SAP Help Portal documentation.
These scripts, originally meant for development and testing, configure OAuth 2.0 clients with hard-coded, well-known credentials.
Tactical Metrics
Metrics
infrastructure
9.1
Software Version
Click for context!
…actions in SAP GUI for HTML, it is not an option for all customers and it is strongly recommended to install the patching ABAP Kernel version."
Also addressed by SAP are two other critical vulnerabilities -
CVE-2026-27690
(CVSS score: 9.1) -
Metrics
victims
2
Client
A use of default credentials flaw in SAP Commerce Cloud that could retain a sample OAuth 2.0 client with publicly documented sample credentials originating from a sample configuration provided in SAP Help Portal documentation.
These scripts, originally meant for development and testing, configure OAuth 2.0 clients with hard-coded, well-known credentials.
Metrics
financial
36,000,000,000
Revenues
The German multinational software corporation has reported total revenues exceeding €36 billion in fiscal year 2025 and servers 99 of the 100 largest companies worldwide.
Intelligence Sources
The Hacker News
2026-07-14
BleepingComputer
2026-07-14
SAP warns of critical flaws in NetWeaver and Commerce Cloud
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-15T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
23x
organisation
Identified Entity
SAP Patches
entity
7x
timeline
Temporal Reference
Jul 14, 2026
date
3x
vulnerability
Exploited CVE
CVE-2026-44747
cve
2x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
2x
tactic
Cyber Operation Type
Ransomware
tactic
2x
general metric
Vulnerabilities
16
vulnerabilities
Contextual Telemetry
Context Block
14 METRICS
vulnerability
CVSS Score
10
score
general metric
Abap Flaw
10
abap flaw
infrastructure
Software Version
9.1
version
general metric
Score
9
score
general metric
Jul
14
jul
victims
Client
2
client
general metric
Oauth
2
oauth
industry
Targeted Sector
Technology
sector
attribution
Attributing Entity
Known Exploited
authority
target region
Target Country
Germany
country
financial
Revenues
36,000,000,000
revenues
general metric
Year
99
year
general metric
Largest Companies
100
largest companies
general metric
%
54
%
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.