SAP June 2026 Security Patch package for NetWeaver and Commerce Cloud
Security Patch Release
Summary
Hide ▲
Show ▼
SAP released fixes for 15 vulnerabilities in its June 2026 Security Patch package, including four critical flaws in SAP NetWeaver and SAP Commerce Cloud that can affect enterprise environments.
Related Happenings
SAP NetWeaver Application Server ABAP SICF workaround for CVE-2026-44747
Advisory/Mitigation
H score40
First: 14.07.2026 21:17
Last: 14.07.2026 21:17
Sources 1
About this happening:
SAP NetWeaver Application Server ABAP customers now have a temporary workaround for CVE-2026-44747 that can reduce exposure to memory corruption. The mitigation disabl...
SAP NetWeaver Application Server ABAP SICF workaround for CVE-2026-44747
Advisory/MitigationAbout this happening: SAP NetWeaver Application Server ABAP customers now have a temporary workaround for CVE-2026-44747 that can reduce exposure to memory corruption. The mitigation disabl...
SAP security patch release for CVE-2026-44747
Security Patch Release
H score40
First: 14.07.2026 21:17
Last: 14.07.2026 21:17
Sources 1
About this happening:
SAP's July 2026 security updates now cover multiple vulnerabilities, including a critical SAP NetWeaver Application Server ABAP flaw. The bundle includes CVE-2026-44...
SAP security patch release for CVE-2026-44747
Security Patch ReleaseAbout this happening: SAP's July 2026 security updates now cover multiple vulnerabilities, including a critical SAP NetWeaver Application Server ABAP flaw. The bundle includes CVE-2026-44...
SAP July 2026 security updates
Security Patch Release
H score31
First: 14.07.2026 14:42
Last: 14.07.2026 14:42
Sources 1
About this happening:
SAP's July 2026 security updates address 16 vulnerabilities across NetWeaver, Commerce Cloud, and AppRouter, including three critical flaws. The release closes a *...
SAP July 2026 security updates
Security Patch ReleaseAbout this happening: SAP's July 2026 security updates address 16 vulnerabilities across NetWeaver, Commerce Cloud, and AppRouter, including three critical flaws. The release closes a *...
SAP July 2026 security patch day
Security Patch Release
H score40
First: 14.07.2026 14:17
Last: 14.07.2026 14:17
Sources 1
About this happening:
SAP released 19 new and updated security notes for its July 2026 security patch day, covering NetWeaver, Approuter, Commerce Cloud, and other products with...
SAP July 2026 security patch day
Security Patch ReleaseAbout this happening: SAP released 19 new and updated security notes for its July 2026 security patch day, covering NetWeaver, Approuter, Commerce Cloud, and other products with...
Fortinet security patch release for CVE-2026-25089
Security Patch Release
H score44
First: 10.06.2026 18:10
Last: 10.06.2026 18:10
Sources 1
About this happening:
Fortinet, Ivanti, and SAP released security updates that address multiple critical vulnerabilities across FortiSandbox, Ivanti Sentry, and SAP prod...
Fortinet security patch release for CVE-2026-25089
Security Patch ReleaseAbout this happening: Fortinet, Ivanti, and SAP released security updates that address multiple critical vulnerabilities across FortiSandbox, Ivanti Sentry, and SAP prod...
Latest development: 11.06.2026 09:20
Shadowserver reported large-scale exploitation attempts against Internet-exposed Ivanti Sentry gateways after CVE-2026-10520 was patched in R10.5.2, R10.6.2, and R10.7.1, saying it saw 19 vulnerable instances and at least 2 backdoored systems and warning that unpatched devices were most likely compromised.
Timeline
-
09.06.2026 22:36 2 articles · 1mo ago
SAP releases June 2026 Security Patch for NetWeaver and Commerce Cloud
Initial DisclosureSAP released fixes for 15 vulnerabilities in its June 2026 Security Patch package, including four critical-severity flaws affecting SAP NetWeaver and SAP Commerce Cloud. The highest-risk issues include CVE-2026-44748, an XML Signature Wrapping flaw that can enable SAML authentication bypass in SAP NetWeaver AS ABAP and ABAP Platform; CVE-2026-27671, a memory corruption flaw in SAP NetWeaver/ABAP Platform Application Server ABAP that can be triggered without authentication through crafted RFC requests; CVE-2026-22732, a Spring Security-related vulnerability affecting SAP Commerce Cloud and SAP Data Hub; and CVE-2026-40128, a directory traversal vulnerability in SAP NetWeaver Application Server Java's Web Container. SAP also addressed two high-severity issues, CVE-2026-29145 and CVE-2026-44751, and recommends that organizations using the impacted products prioritize patching.
Show sources
- SAP fixes critical flaws in NetWeaver and Commerce Cloud — www.bleepingcomputer.com — 09.06.2026 22:36
- SAP fixes critical flaws in NetWeaver and Commerce Cloud — www.bleepingcomputer.com — 09.06.2026 22:36