SAP July 2026 Patch Day: Critical Memory Corruption in NetWeaver ABAP (CVE-2026-44747, CVSS 9.9) Among 16 Security Notes — Threadlinqs Intelligence
As of 2026-07-14, SAP July 2026 Patch Day: Critical Memory Corruption in NetWeaver ABAP (CVE-2026-44747, CVSS 9.9) Among 16 Security Notes is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-1303 · Severity: CRITICAL · CVSS: 9.9 · Status: ACTIVE · Category: VULNERABILITY
SAP's July 2026 Security Patch Day released 16 new security notes, one GitHub security advisory, and three updates to prior notes, headlined by a critical memory corruption vulnerability in NetWeaver
SAP's monthly Security Patch Day for July 2026 (released 2026-07-14) is one of the year's heaviest, bundling 16 new security notes plus a GitHub advisory and three revisions to previously issued notes. The headline issue, CVE-2026-44747 (SAP Note 3747367, CVSS 3.1 base score 9.9, vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, CWE-787 Out-of-bounds Write), is a memory corruption flaw in the SAP NetWeaver Application Server ABAP kernel. Because the flaw sits in the ABAP kernel binary itself rather than an application layer, it spans an unusually wide version matrix: KRNL64NUC/KRNL64UC 7.22 and 7.22EXT, and kernel releases 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19, and 9.20 -- covering roughly two decades of still-supported SAP Basis deployments. An attacker who can reach the ABAP kernel over the network with low-privileged credentials can corrupt memory to affect confidentiality, integrity, and availability, with the CVSS Scope:Changed metric indicating the corruption can affect resources beyond the vulnerable component's own security scope (e.g., escalate out of the kernel dispatcher into other work processes).
Three further critical vulnerabilities round out the top tier. CVE-2026-27690 (SAP Note 3720138, CVSS 9.1) is an HTTP request smuggling flaw in SAP Approuter versions prior to 20.10.0: a specially crafted HTTP request can desynchronize how the Approuter reverse proxy and the back-end application interpret request boundaries, letting an unauthenticated attacker bypass front-end security controls, poison another user's response, or trigger denial of service. CVE-2026-44761 (SAP Note 3753495, CVSS 9.1) affects SAP Commerce Cloud releases HY_COM 2205 and COM_CLOUD 2211/2211-JDK21, where insecure, apparently hardcoded sample/default credentials shipped with the product (CWE-798-class weakness) can grant an attacker unauthorized access to affected environments. CVE-2026-40128 (SAP Note 3727078, CVSS 9.0, originally published 2026-06-09 and re-surfaced in the consolidated July bulletin) is a directory traversal in the NetWeaver AS Java Web Container: an unauthenticated attacker can craft a malicious HTTP logon request that manipulates file-inclusion parameters to escape the intended application context, causing the server to process an unintended local file, exposing or corrupting sensitive data, or degrading availability.
Beyond the four >=9.0 flaws, the same patch day addresses a broad tail of high-severity issues (CVSS 7.6-8.8): three Apache Camel vulnerabilities bundled into SAP Integration Suite (CVE-2026-40860, CVE-2026-40453, CVE-2026-33454, 8.8), a DLL hijacking flaw in SAProuter for Windows (CVE-2026-0487, 8.4, CWE-427 Uncontrolled Search Path Element), cross-site scripting in the NetWeaver Configuration Wizard (CVE-2026-44752, 8.2), an open redirect in SAP Approuter (CVE-2026-44745, 8.1), three bundled Apache Tomcat vulnerabilities in Commerce Cloud (CVE-2026-43512, CVE-2026-41293, CVE-2026-43515, 8.1), and a remote code execution flaw in the Change and Transport System (CTS) Attach Tool (CVE-2026-58233, 7.6). Medium-severity notes cover SQL injection, additional XSS, missing authorization checks, and path traversal issues (4.1-6.1), and low-priority notes cover information disclosure and a residual Log4j-related advisory (3.3-3.7).
As of publication, no source confirms in-the-wild exploitation of any July 2026 SAP CVE, and none of the four headline CVEs currently appear in the CISA Known Exploited Vulnerabilities catalog. However, SAP NetWeaver has a well-established history of rapid n-day weaponization after Patch Tuesday disclosures (the KEV catalog already lists several older SAP NetWeaver Visual Composer, Invoker Servlet, and Universal Worklist flaws as confirmed exploited), and the prior month's SAP June 2026 Patch Day disclosed two similarly critical NetWeaver AS ABAP flaws -- CVE-2026-44748 (XML Signature Wrapping in SAML authentication, CVSS 9.9) and CVE-2026-27671 (unauthenticated RFC-protocol memory co
Weaknesses (CWE)
CWE-787, CWE-444, CWE-798, CWE-1392, CWE-22, CWE-427, CWE-79, CWE-502
Target sectors: government administration, finance, manufacturing, retail, energy, health, technology
Target regions: Global, North America, Europe, Asia Pacific
Related threats
- SAP Patches CVSS 9.9 NetWeaver ABAP Out-of-Bounds Write Flaw (CVE-2026-44747), Plus Critical Approuter and Commerce Cloud Bugs
- SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761)
- Multiple Fluentd Vulnerabilities: RCE via Tag Placeholder (CVE-2026-44024), Info Disclosure (CVE-2026-44025), Decompression Bomb DoS (CVE-2026-44160), and SSRF (CVE-2026-44161)
- CVE-2026-52830: Path Traversal in fast-mcp-telegram Bearer Token Validation Exposes Telegram Session Files
- Adobe Patches Seven Priority-1 ColdFusion and Campaign Classic Flaws (CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48282, CVE-2026-48316, CVE-2026-48286)
- WinRAR 7.23 Fixes Heap Overflow in RAR5 Recovery Volume Processing (CVE-2026-14191)
Detections & IOCs
As of 2026-07-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-44747, CVE-2026-27690, CVE-2026-44761, CVE-2026-40128, CVE-2026-58233, CVE-2026-0487, CVE-2026-44752, CVE-2026-44745, CVE-2026-40860, CVE-2026-40453, T1595, T1588, T1190, T1059, T1203, T1204, T1574, T1078, T1068, T1211