Heise.De
Critical SAP Vulnerabilities Require Immediate Patching
Article Content
SAP has released security updates addressing 15 vulnerabilities, including four critical ones affecting SAP NetWeaver and SAP Commerce Cloud. The vulnerabilities include CVE-2026-44748, allowing authenticated attackers to forge signed XML documents, and CVE-2026-27671, which enables unauthenticated attackers to exploit improper RFC protocol validation, potentially leading to memory corruption. Other critical vulnerabilities include CVE-2026-40128, a Directory Traversal flaw, and CVE-2026-22732, affecting Spring Security. Organizations using these products are urged to patch immediately, as exploitation could lead to unauthorized access and system disruptions. No active exploitation has been reported yet. The vulnerabilities were disclosed on June 9, 2026, and are part of SAP's June security patch package.
Key Points: • SAP released patches for 15 vulnerabilities, including four critical ones. • CVE-2026-44748 and CVE-2026-27671 pose significant risks of unauthorized access and system disruption. • Organizations must prioritize patching to mitigate potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.