hacker-news · Crawled Jul 14, 2026

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data

Read original article ↗

AI Summary

SAP has released security updates to address multiple critical vulnerabilities, including CVE-2026-44747, a CVSS 9.9 out-of-bounds write flaw in SAP NetWeaver ABAP that could allow authenticated attackers to cause memory corruption and potentially access or modify sensitive data. Two other critical flaws were also patched: CVE-2026-27690, an HTTP smuggling vulnerability in SAP Approuter, and CVE-2026-44761, a default credentials issue in SAP Commerce Cloud stemming from sample configuration scripts. Although no active exploitation has been observed, attackers could leverage these flaws to gain unauthorized access, manipulate data, or cause denial-of-service conditions if left unpatched.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.