Bg ShapeBg Shape
THREAT INTELLIGENCE

SAP Security Patch - July 2026

Affected Environment

Multiple SAP products including SAP NetWeaver Application Server ABAP and Java, SAP Approuter, SAP Commerce Cloud, SAP Integration Suite (Edge Integration Cell), SAProuter on Windows, SAP S/4HANA, SAP Fiori Launchpad, SAP HANA, SAP Business Objects, and SAP CRM WebClient UI.

Threat Overview

SAP released its July 2026 Security Patch Day addressing 19 CVEs across its product portfolio, several rated Critical (CVSS up to 9.9) or High. The most severe issues include memory corruption in NetWeaver AS ABAP enabling unauthorized data access or system unavailability, HTTP request smuggling in SAP Approuter exposing user responses, insecure sample OAuth2 credentials in SAP Commerce Cloud allowing unauthenticated API access, and directory traversal in NetWeaver AS Java allowing file access or denial of service. An Apache Camel deserialization vulnerability in SAP Integration Suite enables remote code execution, and a DLL hijacking flaw in SAProuter on Windows enables arbitrary code execution without authentication.

Exposure Timeline

Patch Day published 14 July 2026. No active exploitation confirmed at time of publication. The combination of critical CVSS scores and unauthenticated attack vectors across several CVEs warrants immediate patching. The standard recommended remediation window is ten working days.

Attack Surface

The attack surface varies by CVE. CVE-2026-27690, CVE-2026-44761, CVE-2026-40128, and CVE-2026-0487 are exploitable without authentication. CVE-2026-44747 and CVE-2026-40860 require authenticated access. Internet-exposed SAP instances, particularly NetWeaver AS Java and SAP Approuter endpoints, represent the highest-risk exposure points.

Operational Impact

CVE-2026-44747 (CVSS 9.9) enables memory corruption in NetWeaver AS ABAP, potentially allowing authenticated attackers to access, modify, or destroy data and cause system unavailability. CVE-2026-27690 (CVSS 9.1) allows HTTP request smuggling in SAP Approuter, enabling unauthenticated attackers to expose user session data. CVE-2026-44761 (CVSS 9.1) exposes sample OAuth2 credentials in SAP Commerce Cloud that, if unchanged, allow unauthenticated attackers to obtain valid access tokens and invoke APIs to read and modify data. CVE-2026-40128 (CVSS 9.0) enables path traversal in NetWeaver AS Java, allowing unauthenticated attackers to read, modify, or deny access to sensitive files. CVE-2026-40860 (CVSS 8.8) enables RCE through Apache Camel deserialization in SAP Integration Suite. CVE-2026-0487 (CVSS 8.4) allows unauthenticated DLL hijacking on SAProuter for Windows, enabling arbitrary code execution.

Strategic Impact

Risk is rated Critical for large and medium government and business entities, and High for small entities. SAP systems underpin core business processes across finance, supply chain, HR, and procurement. Compromise of NetWeaver or Commerce Cloud at this severity level poses risk of data exfiltration, process manipulation, and extended system unavailability. The breadth of the patch set, spanning 19 CVEs across core and peripheral SAP products, reflects the sustained attention SAP infrastructure receives from threat actors.

Required Mitigation

Apply all SAP July 2026 Security Notes via SAP Support Portal immediately. Priority remediation should focus on CVE-2026-44747, CVE-2026-27690, CVE-2026-44761, CVE-2026-40128, CVE-2026-40860, and CVE-2026-0487 given their CVSS scores and unauthenticated or low-privilege attack vectors. For CVE-2026-44761 specifically, organisations should audit SAP Commerce Cloud for the presence of unchanged sample OAuth2 credentials and revoke them regardless of patch status.

Apply the Principle of Least Privilege across all SAP systems and services. Use vulnerability management tooling to assess all SAP endpoints and verify remediation status. Ensure perimeter and endpoint security products carry current signatures.

Incident Response Guidance

Review SAP system logs for anomalous authentication events, unexpected API calls, and file access patterns inconsistent with normal operations. For CVE-2026-44761, audit OAuth2 client configurations and revoke any sample or undocumented credentials immediately. Monitor NetWeaver AS Java for unexpected file access or HTTP requests with path traversal patterns. Forward SAP application logs to a centralised SIEM for correlation. Engage SAP Basis and security teams to validate patch application and confirm remediation across the full estate.

References

SAP Security Notes - July 2026: support.sap.com/en/my-support/knowledge-base/security-notes-news/july-2026.html. CVEs: CVE-2026-44747, CVE-2026-27690, CVE-2026-44761, CVE-2026-40128, CVE-2026-40860, CVE-2026-0487, CVE-2026-44752, CVE-2026-44745, CVE-2026-43512, CVE-2026-41293, CVE-2026-43515, CVE-2026-58233, CVE-2026-44759, CVE-2026-44767, CVE-2026-44769, CVE-2026-44760, CVE-2026-44771, CVE-2026-44770, CVE-2026-24315, CVE-2026-44768, CVE-2026-44753, CVE-2025-68161.

Download the Full Report

Explore More of the Latest Threat Intelligence

Trusted by clients worldwide

Logo
Logo
Logo
Logo
Logo
Logo

Your 24/7 Security Partner

Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.

Awards Image
Awards Image
Awards Image
Awards Image
Awards Image
Awards Image