【Vulnerability Alert】SAP Issues Critical Security Advisories for Multiple Products_20260716

publish date : 2026-07-17 update date : 2026-07-17

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026071601073131 Publication Time 2026-07-16 13:24:31
Incident Type ANA-Vulnerability Alert Discovery Time 2026-07-16 13:24:31
Impact Level Low  
[Subject]
【Vulnerability Alert】SAP Issues Critical Security Advisories for Multiple Products
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202607-00000008

【CVE-2026-44747, CVSS: 9.9】SAP NetWeaver Application Server ABAP allows an authenticated attacker to exploit a logic error in memory management to cause memory corruption, resulting in unauthorized data access, modification, or system unavailability.

【CVE-2026-27690, CVSS: 9.1】SAP Approuter contains an HTTP Request Smuggling vulnerability. An unauthenticated attacker may send specially crafted HTTP requests, causing requests and responses to become desynchronized, resulting in the disclosure of user response data and affecting system availability.

【CVE-2026-44761, CVSS: 9.1】SAP Commerce Cloud may retain a sample OAuth2 client containing publicly documented sample credentials derived from the sample configuration provided in the SAP Help Portal documentation. An unauthenticated attacker may use the publicly available credentials to obtain a valid token and call certain APIs to read and modify data.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

SAP NetWeaver Application Server ABAP Version(s) - KRNL64NUC 7.22, 722EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19, 9.20

SAP Approuter Version(s) - SAP Approuter node.js package < 20.10.0

SAP Commerce Cloud Version(s) - HY_COM 2205, COM_CLOUD 2211, 2211-JDK21

[Recommended Actions]

Apply the patches according to the remediation instructions released on the official website: https://support.sap.com/en/my-support/knowledge-base/security-notes-news/july-2026.html

[Reference]

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center