SAP’s July 2026 Security Patch Day, released on 14th July 2026, addressed 16 new security issues, alongside three updates to previously issued notes, with two critical flaws in NetWeaver and AppRouter topping the list.
The most severe issue, tracked as CVE-2026-44747 and carrying a maximum CVSS score of 9.9, is a memory corruption vulnerability in SAP NetWeaver Application Server ABAP.
According to SAP’s advisory, the flaw allows an attacker to exploit logical errors in memory management, triggering memory corruption on affected kernel versions.
SAP July 2026 Patch Day Fixes Critical Flaws
The vulnerability spans a wide range of kernel releases, including KRNL64NUC and KRNL64UC 7.22 through 7.22EXT, and KERNEL 7.22 through 9.20, making it relevant to both legacy and current NetWeaver deployments.
Given the criticality rating, organizations running any of the listed kernel versions should prioritize patch deployment via SAP Note 3747367.
A second critical flaw, CVE-2026-27690 (CVSS 9.1), affects the SAP Approuter node.js package prior to version 20.10.0 and enables HTTP Request Smuggling.
Approuter sits at the front of many SAP BTP and Cloud Foundry application landscapes, routing incoming requests to backend microservices, so smuggling attacks here could let a malicious actor bypass authentication layers or poison downstream caches.
Additional Critical and High Priority Fixes
SAP also patched insecure sample credentials in SAP Commerce Cloud (CVE-2026-44761, CVSS 9.1) affecting HY_COM 2205 and COM_CLOUD 2211 releases.
Among High priority notes, a DLL Hijacking vulnerability in SAProuter on Windows (CVE-2026-0487, CVSS 8.4) and multiple Apache Camel vulnerabilities within SAP Integration Suite’s Edge Integration Cell (CVE-2026-40860, CVSS 8.8) stand out for their broad exploitability.
An RCE flaw in the Change and Transport System Attach Tool (CVE-2026-58233, CVSS 7.6) and multiple Apache Tomcat vulnerabilities bundled in Commerce Cloud (CVSS 8.1) round out the high-severity fixes.
Three earlier security notes received updates this cycle. SAP Note 3727078, covering the June 2026 directory traversal flaw in NetWeaver AS Java’s Web Container (CVE-2026-40128, CVSS 9.0), was revised, as were the SAP Fiori launchpad path traversal note (CVE-2026-24315) and a note addressing the Apache Log4j library used in NetWeaver AS Java (CVE-2025-68161).
Medium and Low Severity Notes
The remaining notes cover a mix of XSS, SQL injection, and missing authorization issues across S/4HANA, SAP CRM WebClient UI, and NetWeaver Enterprise Portal, all rated Medium or Low severity.
A notable inclusion is GHSA-p8gx-753q-v89p, a GitHub security advisory for CVE-2026-44767, an allowlist bypass in ui5/webcomponents-base’s setThemeRoot() function that enables cross-origin CSS injection.
Key July 2026 SAP fixes at a glance:
CVEComponentPriorityCVSSCVE-2026-44747NetWeaver AS ABAPCritical9.9CVE-2026-27690SAP ApprouterCritical9.1CVE-2026-44761SAP Commerce CloudCritical9.1CVE-2026-40860Integration Suite (Edge)High8.8CVE-2026-0487SAProuter (Windows)High8.4
According to the SAP advisory, it strongly recommends that customers apply these patches through the SAP Support Portal without delay, given multiple critical, network-exploitable flaws affecting core infrastructure components.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.