SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761) — Threadlinqs Intelligence
As of 2026-07-14, SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1302 · Severity: CRITICAL · CVSS: 9.9 · Status: ACTIVE · Category: VULNERABILITY
SAP's July 2026 Security Patch Day fixes three critical (CVSS 9.1-9.9) vulnerabilities: an authenticated out-of-bounds write / memory corruption flaw in NetWeaver Application Server ABAP
On its July 2026 Security Patch Day, SAP released 16 security notes (3 critical, 6 high, 7 medium, 1 low), including three HotNews/Critical-rated fixes that stand out for their pre-authentication or low-privilege reachability against internet-facing SAP components.
CVE-2026-44747 (SAP Security Note 3747367, CWE-787 Out-of-Bounds Write, CVSS 3.1 base 9.9) affects SAP NetWeaver Application Server ABAP and ABAP Platform kernel across a wide range of releases (KRNL64NUC 7.22/7.22EXT, KRNL64UC 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, and 9.16 through 9.20). An authenticated attacker holding only low (normal-user) privileges can trigger logical errors in ABAP kernel memory management that corrupt process memory, with a high impact on confidentiality, integrity, and availability. Because the ABAP kernel underpins nearly every classic SAP business application (ERP, S/4HANA on-prem, BW), a successful trigger can lead to unauthorized data access, data tampering, potential privilege escalation, and full application-server crashes/DoS across dependent business processes.
CVE-2026-27690 affects SAP Approuter, the Node.js reverse-proxy middleware that fronts SAP Business Technology Platform (BTP) Cloud Foundry applications, in versions earlier than 20.10.0 (CVSS 3.1 base 9.1). The flaw is an HTTP request smuggling vulnerability reachable by a completely unauthenticated attacker who sends a specially crafted HTTP request that desynchronizes how the front-end proxy and back-end application parse request boundaries (classic CL.TE / TE.CL smuggling class). A successful smuggle can hijack or poison another user's HTTP response (leaking session data, tokens, or otherwise-private application responses), bypass front-end access-control/WAF logic that assumes request/response pairing, or induce denial-of-service by desynchronizing the connection queue. Because Approuter is the internet-facing ingress for BTP multi-tenant SaaS extensions, this is a network-perimeter-exposed bug with no authentication prerequisite.
CVE-2026-44761 affects SAP Commerce Cloud (HY_COM 2205, COM_CLOUD 2211, and 2211-JDK21) (CVSS 3.1 base 9.1, CWE class: use of hard-coded/default credentials). The product ships or retains a sample OAuth2 client whose client_id/client_secret pair is publicly documented in SAP Help Portal reference material for demo/sample configuration. If an administrator does not rotate these documented sample credentials post-deployment, an unauthenticated attacker can request an OAuth2 access token using the published sample client and use that token to call Commerce Cloud OCC/Admin APIs to read and modify commerce data (catalogs, customer data, orders), with high confidentiality and integrity impact and no direct availability impact.
None of the three 2026-Jul CVEs had confirmed in-the-wild exploitation at disclosure time. However, SAP products are a standing ransomware and espionage target: CISA's KEV catalog lists 14 SAP vulnerabilities as exploited since November 2021, including CVE-2017-12637 (NetWeaver directory traversal), CVE-2019-0344 (Commerce Cloud deserialization), CVE-2025-42999 (NetWeaver deserialization), and most notably CVE-2025-31324 (NetWeaver Visual Composer unrestricted file upload, actively exploited pre-patch by threat actors linked to the Russian-speaking ransomware ecosystem — Qilin RaaS affiliates, plus reporting connecting exploitation activity to BianLian and RansomEXX). This precedent — pre-auth or default-credential SAP internet-facing components being weaponized within weeks of disclosure by opportunistic and ransomware-affiliated actors — is the primary reason these three July 2026 flaws warrant detection coverage and rapid patch prioritization even absent confirmed exploitation.
The June 2026 SAP Patch Day (the preceding month) followed the same pattern: four HotNews vulnerabilities including CVE-2026-44748 (XML Signature Wrapping in SAML auth for NetWeaver AS ABAP, CVSS 9.9), CVE-2026-27671 (unauthenticated RFC-based mem
Weaknesses (CWE)
CWE-787, CWE-444, CWE-798, CWE-772
Target sectors: manufacturing, finance, retail, government administration, energy, health, technology, logistics
Target regions: Global, North America, Europe, Asia Pacific
Timeline
- CISA begins cataloguing SAP vulnerabilities as Known Exploited Vulnerabilities; 14 SAP CVEs added to the KEV catalog to date, underscoring SAP as a persistent exploitation target
- CVE-2025-31324 (NetWeaver Visual Composer unrestricted file upload) actively exploited pre-patch; activity linked to Russian-speaking ransomware affiliates including Qilin, BianLian, and RansomEXX
- Onapsis threat brief documents the full CVE-2025-31324 attack chain: mass internet scanning, unauthenticated exploitation of /developmentserver/metadatauploader via a Java deserialization gadget chain, deployment of JSP webshells (helper.jsp, cache.jsp, coresap.jsp, forwardsap.jsp, webhelp.jsp, randomized 8-char names) under the <sid>adm OS user, reconnaissance of SecStore.properties, lateral movement to interconnected SAP systems, and secondary opportunistic attackers abusing established webshells to deploy XMRig coin-miners; Forescout attributed one wave to a China-based actor, Trend Micro linked infrastructure to the China-nexus APT group Earth Lamia
- SAP June 2026 Security Patch Day releases four HotNews notes (CVE-2026-44748, CVE-2026-27671, CVE-2026-40128, CVE-2026-22732) affecting NetWeaver ABAP/Java and Commerce Cloud/Data Hub
- SAP July 2026 Security Patch Day publishes 16 security notes (3 critical, 6 high, 7 medium, 1 low), including CVE-2026-44747, CVE-2026-27690, and CVE-2026-44761
- SAP Security Note 3747367 published, patching the NetWeaver AS ABAP kernel out-of-bounds write (CVE-2026-44747)
- SAP publishes guidance to upgrade Approuter to version 20.10.0+ to remediate the HTTP request smuggling flaw (CVE-2026-27690)
- SAP publishes guidance to rotate the sample OAuth2 client credentials in Commerce Cloud to remediate CVE-2026-44761
- BleepingComputer and SecurityWeek report on the July 2026 SAP Security Patch Day, noting no confirmed active exploitation of the three critical CVEs at time of publication
- Cyber Security Agency of Singapore (CSA) issues advisory AL-2026-075 on the critical SAP NetWeaver and Commerce Cloud vulnerabilities
Detections & IOCs
As of 2026-09-04, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-44747, CVE-2026-27690, CVE-2026-44761, CVE-2025-31324, CVE-2025-42999, CVE-2017-12637, CVE-2019-0344, CVE-2026-44748, CVE-2026-27671, CVE-2026-40128, T1190, T1078.001, T1552.001, T1528, T1203, T1685, T1213, T1567, T1565.001, T1499.003