SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
Read original article ↗AI Summary
SAP has released security updates to address multiple critical vulnerabilities, including CVE-2026-44747, a CVSS 9.9 out-of-bounds write flaw in SAP NetWeaver ABAP that could allow authenticated attackers to cause memory corruption and potentially access or modify sensitive data. Two other critical flaws were also patched: CVE-2026-27690, an HTTP smuggling vulnerability in SAP Approuter, and CVE-2026-44761, a default credentials issue in SAP Commerce Cloud stemming from sample configuration scripts. Although no active exploitation has been observed, attackers could leverage these flaws to gain unauthorized access, manipulate data, or cause denial-of-service conditions if left unpatched.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.