SAP Addresses Critical Security Flaws in NetWeaver and Commerce Cloud
SAP fixes critical flaws in NetWeaver and Commerce Cloud

Image: Bleepingcomputer
SAP has released security patches for 15 vulnerabilities, including four critical issues in SAP NetWeaver and SAP Commerce Cloud. Key vulnerabilities include authentication bypass and memory corruption flaws, which require immediate attention from organizations using these platforms.
- 01SAP's June 2026 Security Patch package fixes 15 vulnerabilities, four of which are critical.
- 02CVE-2026-44748 allows authentication bypass in SAML environments, rated CVSS 9.9.
- 03CVE-2026-27671 is a memory corruption flaw that can be exploited without authentication.
- 04Organizations are advised to prioritize patching these critical vulnerabilities to protect sensitive data.
- 05Additional high-severity vulnerabilities and various other issues across SAP products were also addressed.
Advertisement
In-Article Ad
SAP has issued a security patch addressing 15 vulnerabilities, including four critical flaws impacting its core platforms, SAP NetWeaver and SAP Commerce Cloud. NetWeaver serves as the backbone for many SAP applications, while Commerce Cloud supports e-commerce functionalities. Among the critical vulnerabilities, CVE-2026-44748, rated CVSS 9.9, could allow attackers to bypass authentication in SAML-based systems, potentially leading to unauthorized access to sensitive data. Another critical flaw, CVE-2026-27671, involves memory corruption that can be exploited without authentication through crafted requests. Other vulnerabilities include a Spring Security-related issue in Commerce Cloud and a directory traversal flaw in NetWeaver. SAP has also addressed high-severity vulnerabilities related to Apache Tomcat and authorization checks. Organizations utilizing these products are urged to implement the patches promptly to mitigate risks associated with these vulnerabilities, particularly those rated very high in severity.
Advertisement
In-Article Ad
Organizations using SAP NetWeaver and Commerce Cloud must patch critical vulnerabilities to prevent potential data breaches.
Advertisement
In-Article Ad
Reader Poll
How concerned are you about security vulnerabilities in enterprise software?
Connecting to poll...
Read the original article
Visit the source for the complete story.




