SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761) — Threadlinqs Intelligence
As of 2026-07-14, SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1302 · Severity: CRITICAL · CVSS: 9.9 · Status: ACTIVE · Category: VULNERABILITY
SAP's July 2026 Security Patch Day fixes three critical (CVSS 9.1-9.9) vulnerabilities: an authenticated out-of-bounds write / memory corruption flaw in NetWeaver Application Server ABAP
On its July 2026 Security Patch Day, SAP released 16 security notes (3 critical, 6 high, 7 medium, 1 low), including three HotNews/Critical-rated fixes that stand out for their pre-authentication or low-privilege reachability against internet-facing SAP components.
CVE-2026-44747 (SAP Security Note 3747367, CWE-787 Out-of-Bounds Write, CVSS 3.1 base 9.9) affects SAP NetWeaver Application Server ABAP and ABAP Platform kernel across a wide range of releases (KRNL64NUC 7.22/7.22EXT, KRNL64UC 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, and 9.16 through 9.20). An authenticated attacker holding only low (normal-user) privileges can trigger logical errors in ABAP kernel memory management that corrupt process memory, with a high impact on confidentiality, integrity, and availability. Because the ABAP kernel underpins nearly every classic SAP business application (ERP, S/4HANA on-prem, BW), a successful trigger can lead to unauthorized data access, data tampering, potential privilege escalation, and full application-server crashes/DoS across dependent business processes.
CVE-2026-27690 affects SAP Approuter, the Node.js reverse-proxy middleware that fronts SAP Business Technology Platform (BTP) Cloud Foundry applications, in versions earlier than 20.10.0 (CVSS 3.1 base 9.1). The flaw is an HTTP request smuggling vulnerability reachable by a completely unauthenticated attacker who sends a specially crafted HTTP request that desynchronizes how the front-end proxy and back-end application parse request boundaries (classic CL.TE / TE.CL smuggling class). A successful smuggle can hijack or poison another user's HTTP response (leaking session data, tokens, or otherwise-private application responses), bypass front-end access-control/WAF logic that assumes request/response pairing, or induce denial-of-service by desynchronizing the connection queue. Because Approuter is the internet-facing ingress for BTP multi-tenant SaaS extensions, this is a network-perimeter-exposed bug with no authentication prerequisite.
CVE-2026-44761 affects SAP Commerce Cloud (HY_COM 2205, COM_CLOUD 2211, and 2211-JDK21) (CVSS 3.1 base 9.1, CWE class: use of hard-coded/default credentials). The product ships or retains a sample OAuth2 client whose client_id/client_secret pair is publicly documented in SAP Help Portal reference material for demo/sample configuration. If an administrator does not rotate these documented sample credentials post-deployment, an unauthenticated attacker can request an OAuth2 access token using the published sample client and use that token to call Commerce Cloud OCC/Admin APIs to read and modify commerce data (catalogs, customer data, orders), with high confidentiality and integrity impact and no direct availability impact.
None of the three 2026-Jul CVEs had confirmed in-the-wild exploitation at disclosure time. However, SAP products are a standing ransomware and espionage target: CISA's KEV catalog lists 14 SAP vulnerabilities as exploited since November 2021, including CVE-2017-12637 (NetWeaver directory traversal), CVE-2019-0344 (Commerce Cloud deserialization), CVE-2025-42999 (NetWeaver deserialization), and most notably CVE-2025-31324 (NetWeaver Visual Composer unrestricted file upload, actively exploited pre-patch by threat actors linked to the Russian-speaking ransomware ecosystem — Qilin RaaS affiliates, plus reporting connecting exploitation activity to BianLian and RansomEXX). This precedent — pre-auth or default-credential SAP internet-facing components being weaponized within weeks of disclosure by opportunistic and ransomware-affiliated actors — is the primary reason these three July 2026 flaws warrant detection coverage and rapid patch prioritization even absent confirmed exploitation.
The June 2026 SAP Patch Day (the preceding month) followed the same pattern: four HotNews vulnerabilities including CVE-2026-44748 (XML Signature Wrapping in SAML auth for NetWeaver AS ABAP, CVSS 9.9), CVE-2026-27671 (unauthenticated RFC-based mem
Weaknesses (CWE)
CWE-787, CWE-444, CWE-798, CWE-772
Target sectors: manufacturing, finance, retail, government administration, energy, health, technology, logistics
Target regions: Global, North America, Europe, Asia Pacific
Detections & IOCs
As of 2026-07-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-44747, CVE-2026-27690, CVE-2026-44761, CVE-2025-31324, CVE-2025-42999, CVE-2017-12637, CVE-2019-0344, CVE-2026-44748, CVE-2026-27671, CVE-2026-40128, T1190, T1078.001, T1552.001, T1528, T1203, T1562.001, T1213, T1567, T1565.001, T1499.003