Skip to content

Warning: SAP Addresses Critical Vulnerabilities Affecting Multiple SAP products, Patch Immediately!

Ccb.Belgium.Be June 9, 2026

SAP has released fifteen security updates addressing a range of vulnerabilities across its core SAP products, including four critical vulnerabilities that require immediate attention from organizations.

CVE-2026-44748 is an XML signature vulnerability that could allow an authenticated attacker with low privileges to forge signed XML documents. Successful exploitation could enable the tampering of identity information, resulting in unauthorized access to sensitive user data and potential disruption of normal systems operations.

CVE-2026-27671 is an Improper RFC protocol validation in SAP Kernel. An unauthenticated attacker could send a crafted RFC request to corrupt the memory in the SAP Kernel, potentially leading to application crash, unauthorize data access or arbitrary code execution.

CVE-2026-40128 is a Directory Traversal vulnerability that allows an unauthenticated attacker over the network to craft malicious HTTP logon requests to traverse the file system and process arbitrary files, allowing them to read sensitive information, modify files, or crash the application.

CVE-2026-22732 is a Spring Security vulnerability within SAP Commerce Cloud and SAP Data Hub, enabling unauthenticated remote attackers to impact confidentiality and integrity without user interaction. No active exploitation of these vulnerabilities has been observed in the wild.

CVE-2026-44748 is an XML signature vulnerability with a CVSS score of 9.9 affecting SAP NetWeaver Application Server ABAP and ABAP Platform. This critical vulnerability involves an XML signature weakness withing the SAML authentication, which could allow an authenticated attacker with standard privileges to obtain valid signed messages and subsequently submit modifies signed XML documents to the verification component.

CVE-2026-27671 is a critical vulnerability (CVSS core 9.8) within the Application Server ABAP Kernel arising from improper validation of the RFC protocol, resulting to memory corruption condition. An unauthenticated attacker could exploit this vulnerability by sending crafted RFC request that targets memory management process. Successful exploitation could lead to severe disruption of system stability and a significant impact on application availability.

CVE-2026-40128 is a critical Directory Traversal vulnerability (with a CVSS score of 9.0) within the SAP NetWeaver Application Server Java (Web Container). This vulnerability could allow unauthenticated attacker to craft malicious HTTP logon requests. These requests manipulate the file inclusion parameters to view or modify protected server logs.

CVE-2026-22732 is also a critical vulnerability (with CVSS score 9.1) in the Spring Security servlet support layer. When applications configure Spring Security to write HTTP security response headers, those headers may, under certain conditions, not be written to the response at all. Consequently, this exposure leaves downstream web clients vulnerable to advanced connection hijacking.

The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority after thorough testing.

The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity and ensure a swift response in case of an intrusion.

In case of an intrusion, you can report an incident via .

While patching appliances or software to the newest version may protect against future exploitation, it does not remediate historic compromise.