Back Heise.De Partially critical security vulnerabilities fixed in several products
The developers at SAP have released 16 new security notes for the July Patch Day . Three of these address vulnerabilities classified as critical risks in several products.
In the Patch Day overview, SAP lists the individual advisories clearly. A potential memory access error due to logic flaws in the memory management of SAP NetWeaver Application Server ABAP, which could allow authenticated attackers to gain unauthorized access to data and, for example, modify it or even cause a denial-of-service, is close to the highest rating ( CVE-2026-44747 , CVSS 9.9 , Risk “ critical ”). In SAP Approuter, malicious actors can inject HTTP requests that allow unauthenticated attackers to disrupt the synchronization of requests and responses. This leads to the disclosure of user responses or system downtime ( CVE-2026-27690 , CVSS 9.1 , Risk “ critical ”). A default and publicly documented example account for the OAuth2 client also compromises the security of SAP Commerce Cloud. Attackers can use it to log in and read and manipulate data, SAP explains ( CVE-2026-44761 , CVSS 9.1 , Risk “ critical ”).
The Apache Camel component of SAP Integration Suite exposes several security vulnerabilities (CVE-2026-40453, CVE-2026-33454; up to CVSS 8.8 , Risk “ high ”). Additionally, SAProuter on Windows has a DLL hijacking vulnerability (CVE-2026-0487, CVSS 8.4 , Risk “ high ”). In SAP NetWeaver Application Server Java (Configuration Wizard), there is a cross-site scripting vulnerability (CVE-2026-44752, CVSS 8.2 , Risk “ high ”), and SAP Approuter may act as an open redirect (CVE-2026-44745, CVSS 8.1 , Risk “ high ”). The Apache Tomcat server of SAP Commerce Cloud also exposes several vulnerabilities (CVE-2026-43512, CVE-2026-41293, CVE-2026-43515; up to CVSS 8.1 , Risk “ high ”). The SAP Change and Transport System Attach Tool (ctsattach) also contains a code smuggling vulnerability (CVE-2026-58233, CVSS 7.6 , Risk “ high ”).
Security vulnerabilities with a medium threat level affect SAP NetWeaver Enterprise Portal, ui5/webcomponents-base, SAP S/4HANA Project Management (PPM-PRO), SAP NetWeaver Application Server ABAP (applications based on Business Server Pages), SAP S/4HANA (Draft operation), S/4 HANA (Create Single Payment), and SAP CRM (WebClient UI). In SAP HANA Extended Application Services classic model (User Self Service), developers have also closed a vulnerability classified as “ low ” risk.
IT managers should apply the available updates promptly to minimize the attack surface in their networks. The SAP Patch Day in June had a similar scope. There, developers had fixed 15 security vulnerabilities, three of which were also classified as critical.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
