Critical SAP Vulnerabilities Require Immediate Patching

Critical SAP Vulnerabilities Require Immediate Patching

First seen 9 Jun 2026, 15:44 UTC Heise.Denvd.nist.govCcb.Belgium.BeBleepingcomputerCsa.Sg+2 89% similarity 72.0

Article Content

Browse articles
ThreatCluster

SAP has released security updates addressing 15 vulnerabilities, including four critical ones affecting SAP NetWeaver and SAP Commerce Cloud. The vulnerabilities include CVE-2026-44748, allowing authenticated attackers to forge signed XML documents, and CVE-2026-27671, which enables unauthenticated attackers to exploit improper RFC protocol validation, potentially leading to memory corruption. Other critical vulnerabilities include CVE-2026-40128, a Directory Traversal flaw, and CVE-2026-22732, affecting Spring Security. Organizations using these products are urged to patch immediately, as exploitation could lead to unauthorized access and system disruptions. No active exploitation has been reported yet. The vulnerabilities were disclosed on June 9, 2026, and are part of SAP's June security patch package.

Key Points: • SAP released patches for 15 vulnerabilities, including four critical ones. • CVE-2026-44748 and CVE-2026-27671 pose significant risks of unauthorized access and system disruption. • Organizations must prioritize patching to mitigate potential exploitation.

ThreatCluster AI

Timeline

2026-04-09
CVE-2026-29145 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-09
SAP releases June 2026 Security Patch package
SAP addresses 15 vulnerabilities, including four critical flaws in NetWeaver and Commerce Cloud, urging immediate action from organizations.
Ccb.Belgium.Be
2026-06-09
CVE-2026-44748 published
This vulnerability allows authenticated attackers to forge signed XML documents, potentially leading to unauthorized access.
Bleepingcomputer
2026-06-09
CVE-2026-27671 published
An unauthenticated attacker can exploit this vulnerability to cause memory corruption in SAP Kernel, impacting system stability.
Heise.De
2026-06-09
CVE-2026-40128 published
This Directory Traversal vulnerability allows unauthenticated attackers to manipulate file inclusion parameters, risking sensitive data exposure.
Ccb.Belgium.Be
2026-06-09
CVE-2026-22732 published
A vulnerability in Spring Security that may leave web clients vulnerable to connection hijacking due to improper HTTP header handling.
nvd.nist.gov
2026-06-09
CVE-2026-44751 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

Community

Browse all →