• News/
  • bleepingcomputer-20260609193627

SAP fixes critical flaws in NetWeaver and Commerce Cloud

BleepingComputer
·
Bill Toulas
·
Published Jun 9, 2026
·
Updated

SAP has released fixes for 15 vulnerabilities as part of its June 2026 Security Patch package, including four critical-severity flaws affecting SAP NetWeaver and SAP Commerce Cloud. NetWeaver is SAP's core application platform and middleware stack that provides the foundation for many SAP business applications, including ERP systems, handling functions such as application serving, integration, authentication, user management, and data processing. Commerce Cloud is an enterprise e-commerce platform (formerly Hybris). It enables organizations to build and manage online stores, digital sales channels, product catalogs, customer accounts, and order management systems for B2B and B2C commerce. In this month's security bulletin, SAP lists the following critical vulnerabilities as being addressed: “SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier,” reads the description for CVE-2026-44748. “This may result in acceptance of tampered identity information leading to unauthorized access to sensitive user data and potential disruption of normal system usage.” In the case of CVE-2026-27671, an attacker can exploit it without authentication by sending crafted RFC requests to vulnerable endpoints, leveraging improper kernel validation to cause memory corruption. Apart from the critical security issues above, SAP also addressed two high-sever...

Read full article

Affected Software

3 affected components
SAP NetWeaver Application Server ABAP and ABAP Platform
SAP NetWeaver AS ABAP
SAP Commerce Cloud
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses SAP's release of security fixes for vulnerabilities in NetWeaver and Commerce Cloud.

2

What security implications are discussed in the article?

The article highlights that four critical-severity vulnerabilities in SAP NetWeaver and Commerce Cloud could pose significant security risks to users.

3

What products or software are affected by the vulnerabilities?

The affected products include SAP NetWeaver Application Server ABAP, ABAP Platform, and SAP Commerce Cloud.

4

How many vulnerabilities were fixed in the June 2026 Security Patch package?

SAP fixed a total of 15 vulnerabilities in the June 2026 Security Patch package.

5

Why is SAP NetWeaver important for businesses?

SAP NetWeaver serves as a core application platform and middleware stack that underpins many SAP business applications.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203