Heise.De
Critical SAP Vulnerabilities Require Immediate Patching
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
SAP has released security updates addressing 15 vulnerabilities, including four critical ones affecting SAP NetWeaver and SAP Commerce Cloud. The vulnerabilities include CVE-2026-44748, allowing authenticated attackers to forge signed XML documents, and CVE-2026-27671, which enables unauthenticated attackers to exploit improper RFC protocol validation, potentially leading to memory corruption. Other critical vulnerabilities include CVE-2026-40128, a Directory Traversal flaw, and CVE-2026-22732, affecting Spring Security. Organizations using these products are urged to patch immediately, as exploitation could lead to unauthorized access and system disruptions. No active exploitation has been reported yet. The vulnerabilities were disclosed on June 9, 2026, and are part of SAP's June security patch package.
Key Points: • SAP released patches for 15 vulnerabilities, including four critical ones. • CVE-2026-44748 and CVE-2026-27671 pose significant risks of unauthorized access and system disruption. • Organizations must prioritize patching to mitigate potential exploitation.