SAP patches critical NetWeaver, Approuter, Commerce Cloud flaws

SAP’s July 2026 security updates fix critical vulnerabilities in NetWeaver ABAP, Approuter and Commerce Cloud. Customers should apply patches and audit for hardcoded OAuth2 client credentials.

SAP released 19 new and updated security notes on its July 2026 security patch day addressing critical vulnerabilities in NetWeaver Application Server ABAP, Approuter and Commerce Cloud. The company told customers to apply patches and to check production systems for any hardcoded OAuth2 client credentials.

The most severe fix addresses a memory corruption flaw in NetWeaver Application Server ABAP tracked as CVE-2026-44747 and rated 9.9 on the CVSS scale. Successful exploitation could allow an attacker to read or alter data or cause system unavailability. SAP updated a NetWeaver security note first issued in June to include additional packages in this release.

SAP also fixed a critical HTTP request smuggling vulnerability in Approuter, CVE-2026-27690, with a CVSS score of 9.1. Security firm Onapsis described the issue as affecting Approuter deployments in non-Cloud Foundry environments and allowing an unauthenticated attacker to send a specially crafted HTTP request that causes request-response desynchronization. As a temporary mitigation, administrators can disable ICF nodes with a specific property in transaction SICF until the patch is applied.

A third critical flaw affects Commerce Cloud and is tracked as CVE-2026-44761, also scored 9.1. The vulnerability stems from sample configuration scripts on the SAP Help Portal that include OAuth2 clients with known secrets. If a customer imports a sample script into production and keeps the default secret, an unauthenticated actor could obtain an access token and call APIs to read or modify data. Onapsis noted that customers who removed the sample client or replaced its secret with a unique value are not affected and urged customers to audit production environments for such clients.

In addition to the three critical fixes, SAP published six security notes covering high-severity defects across Integration Suite (Edge Integration Cell), SAProuter, NetWeaver Application Server Java (Configuration Wizard), Approuter, Commerce Cloud and the Change and Transport System Attach Tool (ctsattach). The notes for Integration Suite and Commerce Cloud include patches for multiple Apache Camel and Apache Tomcat vulnerabilities. Other new and updated notes address medium- and low-severity issues in NetWeaver, S/4HANA, Fiori, CRM and HANA Extended Application Services Classic Model.

SAP recommends that customers apply the NetWeaver ABAP and Approuter updates promptly because of their high severity and potential for unauthenticated exploitation. For Commerce Cloud, SAP recommends auditing any OAuth2 clients created from sample scripts and rotating or removing any default secrets found in production. Where immediate patching is not possible, follow the vendor-supplied temporary mitigations and monitor systems for unusual activity.

The July release continues SAP’s monthly security patch schedule and provides fixes for a range of critical, high, medium and low severity vulnerabilities.

Articles by this author