{"id":13479,"date":"2026-06-09T10:03:40","date_gmt":"2026-06-09T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/09\/sap-security-patch-day-critical-vulnerabilities-in-sap-netweaver-patched\/"},"modified":"2026-06-09T10:03:40","modified_gmt":"2026-06-09T10:03:40","slug":"sap-security-patch-day-critical-vulnerabilities-in-sap-netweaver-patched","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/09\/sap-security-patch-day-critical-vulnerabilities-in-sap-netweaver-patched\/","title":{"rendered":"SAP Security Patch Day \u2013 Critical Vulnerabilities in SAP NetWeaver Patched"},"content":{"rendered":"<p>    SAP Security Patch Day \u2013 Critical Vulnerabilities in SAP NetWeaver Patched<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">SAP\u2019s June 2026 Security Patch Day, observed on Tuesday, June 9, delivered 15 new security notes addressing a broad range of vulnerabilities across core SAP products, including four critical-severity flaws that demand immediate enterprise attention.<\/p>\n<p class=\"wp-block-paragraph\">SAP strongly urges all customers to visit the SAP Support Portal and apply the patches on priority to protect their SAP landscape.<\/p>\n<h2 id=\"h-critical-vulnerabilities-patched\" class=\"wp-block-heading\"><strong>Critical Vulnerabilities Patched<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The most severe flaw patched this cycle is CVE-2026-44748 (CVSS 9.9), an XML Signature Wrapping vulnerability in <a href=\"https:\/\/cybersecuritynews.com\/multiple-jenkins-vulnerability\/\">SAML Authentication<\/a> affecting SAP NetWeaver AS ABAP and ABAP Platform.<\/p>\n<p class=\"wp-block-paragraph\">This flaw allows an authenticated attacker with low privileges to obtain a valid signed message and transmit modified XML documents to the verifier, potentially enabling acceptance of tampered identity information, unauthorized access to sensitive user data, and privilege escalation across enterprise systems. The vulnerability spans an extensive range of SAP_BASIS versions from 702 through 919, making the patch footprint exceptionally wide.<\/p>\n<p class=\"wp-block-paragraph\">A second critical issue, CVE-2026-27671 (CVSS 9.8), targets the Application Server ABAP kernel and introduces a memory corruption risk via improper RFC protocol validation.<\/p>\n<p class=\"wp-block-paragraph\">Unlike the SAML flaw, this vulnerability is unauthenticated; an attacker can send a specially crafted RFC request that exploits logical errors in memory management without any valid credentials, leading to high-impact compromise of confidentiality, integrity, and availability. Affected components include multiple KRNL64NUC, KRNL64UC, and KERNEL versions.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-22732 (CVSS 9.1) patches a <a href=\"https:\/\/cybersecuritynews.com\/spring-security-vulnerability-let-attackers\/\" target=\"_blank\" rel=\"noreferrer noopener\">Spring Security vulnerability<\/a> within SAP Commerce Cloud and SAP Data Hub, enabling unauthenticated remote attackers to impact confidentiality and integrity without user interaction.<\/p>\n<p class=\"wp-block-paragraph\">Completing the critical quartet is CVE-2026-40128 (CVSS 9.0), a Directory Traversal flaw in the SAP NetWeaver Application Server Java Web Container (ENGINEAPI 7.50), where a network-accessible attacker can traverse directory structures to reach sensitive resources under high confidentiality, integrity, and availability impact.<\/p>\n<h2 id=\"h-high-severity-patches\" class=\"wp-block-heading\"><strong>High-Severity Patches<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">SAP also addressed two high-priority notes this cycle. CVE-2026-29145 (CVSS 7.4) bundles multiple Apache Tomcat vulnerabilities \u2014 including CVE-2025-66614 and CVE-2026-24734 within SAP Commerce Cloud (HY_COM 2205, COM_CLOUD 2211), allowing unauthenticated attackers to exploit weaknesses in the embedded Tomcat server.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-44751 (CVSS 7.1) fixes a Missing Authorization Check in SAP NetWeaver AS ABAP and ABAP Platform affecting SAP_BASIS versions 700 through 816, where a low-privileged network attacker could achieve high integrity impact and partial availability disruption.<\/p>\n<h2 id=\"h-medium-and-low-severity-notes\" class=\"wp-block-heading\"><strong>Medium and Low Severity Notes<\/strong><\/h2>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Note #<\/th>\n<th>CVE<\/th>\n<th>Product<\/th>\n<th>Vulnerability Type<\/th>\n<th>CVSS<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>3748819<\/td>\n<td>CVE-2026-44754<\/td>\n<td>ODP Data Replication APIs<\/td>\n<td>Missing Caller Identification<\/td>\n<td>6.6<\/td>\n<\/tr>\n<tr>\n<td>3751691<\/td>\n<td>CVE-2026-44744<\/td>\n<td>SAP S\/4HANA<\/td>\n<td>SQL Injection<\/td>\n<td>6.5<\/td>\n<\/tr>\n<tr>\n<td>3723655<\/td>\n<td>CVE-2026-44746<\/td>\n<td>SAP NetWeaver AS Java (JDBC Test Servlet)<\/td>\n<td>Reflected XSS<\/td>\n<td>6.1<\/td>\n<\/tr>\n<tr>\n<td>3715280<\/td>\n<td>CVE-2026-44757<\/td>\n<td>SAP Wily Introscope Enterprise Manager<\/td>\n<td>Cross-Site Scripting<\/td>\n<td>4.7<\/td>\n<\/tr>\n<tr>\n<td>3673181<\/td>\n<td>CVE-2026-44750<\/td>\n<td>SAP MDG (Review Match Groups)<\/td>\n<td>Missing Authorization<\/td>\n<td>4.3<\/td>\n<\/tr>\n<tr>\n<td>3687096<\/td>\n<td>CVE-2026-44755<\/td>\n<td>SAP BusinessObjects BI Platform<\/td>\n<td>Email Spoofing<\/td>\n<td>4.3<\/td>\n<\/tr>\n<tr>\n<td>3682699<\/td>\n<td>CVE-2026-24315<\/td>\n<td>SAP Fiori (Launchpad)<\/td>\n<td>Path Traversal<\/td>\n<td>4.2<\/td>\n<\/tr>\n<tr>\n<td>3706000<\/td>\n<td>CVE-2026-44743<\/td>\n<td>SAP Business Objects<\/td>\n<td>Security Misconfiguration<\/td>\n<td>3.7<\/td>\n<\/tr>\n<tr>\n<td>3726899<\/td>\n<td>CVE-2025-68161<\/td>\n<td>SAP NetWeaver AS Java<\/td>\n<td>Apache Log4j Exposure<\/td>\n<td>3.3<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">The SQL Injection flaw in SAP S\/4HANA (CVE-2026-44744, CVSS 6.5) poses a notable data exposure risk, allowing authenticated low-privileged attackers to query sensitive database content via crafted inputs across S4FND versions 102 through 109.<\/p>\n<p class=\"wp-block-paragraph\">The Reflected XSS in SAP NetWeaver\u2019s JDBC Test Servlet (CVE-2026-44746) and the Log4j-related advisory in SAP NetWeaver AS Java (CVE-2025-68161) round out the lower-tier patches, though the latter serves as a reminder that third-party library dependencies within SAP products continue to introduce residual risk.<\/p>\n<p class=\"wp-block-paragraph\">Security teams managing SAP environments should prioritize remediation in the following order:<\/p>\n<ol class=\"wp-block-list\">\n<li>\n<strong>CVE-2026-44748<\/strong> \u2013 Apply the SAML XML Signature fix immediately across all SAP_BASIS versions; as a temporary workaround, SAML authentication can be disabled, though this does not cover all signed XML use cases.<\/li>\n<li>\n<strong>CVE-2026-27671<\/strong> \u2013 Patch all affected SAP Kernel versions (7.22\u20139.19) to eliminate the unauthenticated RFC memory corruption vector.<\/li>\n<li>\n<strong>CVE-2026-22732 &amp; CVE-2026-40128<\/strong> \u2013 Update SAP Commerce Cloud, SAP Data Hub, and NetWeaver Java (ENGINEAPI 7.50) to remediate the Spring Security and Directory Traversal flaws<\/li>\n<li>\n<strong>CVE-2026-29145<\/strong> \u2013 Apply the Apache Tomcat bundle patch for SAP Commerce Cloud to address multiple embedded server vulnerabilities<\/li>\n<li>\n<strong>Remaining medium\/low notes<\/strong> \u2013 Schedule within the standard monthly patch management cycle, particularly prioritizing the S\/4HANA SQL injection and NetWeaver AS Java XSS fixes<\/li>\n<\/ol>\n<p class=\"wp-block-paragraph\">SAP Security Patch Day is scheduled for the second Tuesday of every month. Organizations are strongly advised to implement a structured SAP patch management process and monitor the <a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">SAP Security Notes portal<\/a> for any out-of-band updates following this cycle.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/sap-security-patch-day-june\/\">SAP Security Patch Day \u2013 Critical Vulnerabilities in SAP NetWeaver Patched<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/sap-security-patch-day-june\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SAP Security Patch Day \u2013 Critical Vulnerabilities in SAP NetWeaver Patched SAP\u2019s June 2026 Security Patch Day, observed on Tuesday, June 9, delivered 15 new security notes addressing a broad range of vulnerabilities across core SAP products, including four critical-severity flaws that demand immediate enterprise attention. SAP strongly urges all customers to visit the SAP [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-13479","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13479"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13479"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13479\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13479"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13479"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13479"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}