SAP has released fixes for 15 vulnerabilities as part of its June 2026 Security Patch package, including four critical-severity flaws affecting SAP NetWeaver and SAP Commerce Cloud. NetWeaver is SAP's core application platform and middleware stack that provides the foundation for many SAP business applications, including ERP systems, handling functions such as application serving, integration, authentication, user management, and data processing. Commerce Cloud is an enterprise e-commerce platform (formerly Hybris). It enables organizations to build and manage online stores, digital sales channels, product catalogs, customer accounts, and order management systems for B2B and B2C commerce. In this month's security bulletin, SAP lists the following critical vulnerabilities as being addressed: “SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier,” reads the description for CVE-2026-44748. “This may result in acceptance of tampered identity information leading to unauthorized access to sensitive user data and potential disruption of normal system usage.” In the case of CVE-2026-27671, an attacker can exploit it without authentication by sending crafted RFC requests to vulnerable endpoints, leveraging improper kernel validation to cause memory corruption. Apart from the critical security issues above, SAP also addressed two high-sever...
SAP fixes critical flaws in NetWeaver and Commerce Cloud
BleepingComputer
·Bill Toulas
·Published Jun 9, 2026
·Updated
Affected Software
3 affected components
SAP NetWeaver Application Server ABAP and ABAP Platform
SAP NetWeaver AS ABAP
SAP Commerce Cloud
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses SAP's release of security fixes for vulnerabilities in NetWeaver and Commerce Cloud.
2
What security implications are discussed in the article?
The article highlights that four critical-severity vulnerabilities in SAP NetWeaver and Commerce Cloud could pose significant security risks to users.
3
What products or software are affected by the vulnerabilities?
The affected products include SAP NetWeaver Application Server ABAP, ABAP Platform, and SAP Commerce Cloud.
4
How many vulnerabilities were fixed in the June 2026 Security Patch package?
SAP fixed a total of 15 vulnerabilities in the June 2026 Security Patch package.
5
Why is SAP NetWeaver important for businesses?
SAP NetWeaver serves as a core application platform and middleware stack that underpins many SAP business applications.