SAP Patches CVSS 9.9 NetWeaver ABAP Out-of-Bounds Write Flaw (CVE-2026-44747), Plus Critical Approuter and Commerce Cloud Bugs — Threadlinqs Intelligence
As of 2026-07-14, SAP Patches CVSS 9.9 NetWeaver ABAP Out-of-Bounds Write Flaw (CVE-2026-44747), Plus Critical Approuter and Commerce Cloud Bugs is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1329 · Severity: CRITICAL · CVSS: 9.9 · Status: PATCHED · Category: VULNERABILITY
SAP's July 2026 Security Patch Day fixed CVE-2026-44747 (CVSS 9.9), a CWE-787 out-of-bounds write in NetWeaver Application Server ABAP that lets an authenticated, low-privileged attacker corrupt
On its July 2026 Security Patch Day, SAP released 16 new security notes (plus one GitHub advisory) addressing 6 critical, 6 high, 7 medium, and 1 low-severity issues across the NetWeaver, Approuter, and Commerce Cloud product lines. The headline flaw, CVE-2026-44747, is a CWE-787 out-of-bounds write in the SAP NetWeaver Application Server ABAP runtime — the kernel-level execution environment underpinning most classic SAP ERP, S/4HANA, and custom ABAP application deployments. SAP describes the root cause as 'logical errors in memory management': an authenticated user (PR:L, low privileges required, no user interaction) can trigger heap/stack memory corruption through crafted requests processed by the ABAP kernel. Because the scope is Changed (S:C) in the CVSS vector, corruption in the kernel process can affect resources beyond the vulnerable component's own security authority — a hallmark of kernel-level memory-safety bugs that can pivot from a low-privilege session into broader confidentiality (C:H), integrity (I:H), and availability (A:H) impact, including unauthorized data access, data tampering, or a full application-server outage. The vulnerability affects a wide span of ABAP kernel release trains: KRNL64NUC 7.22/7.22EXT, KRNL64UC 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, and 9.16 through 9.20 — spanning nearly two decades of still-supported SAP kernel branches, reflecting how long-lived and rarely-patched production ABAP stacks tend to be. SAP's advisory (Security Note 3747367) recommends installing the patched ABAP Kernel version as the permanent fix; as an interim compensating control, Onapsis notes that administrators can disable ICF (Internet Communication Framework) service nodes carrying a specific property via transaction SICF, though this breaks SAP GUI for HTML (WebGUI) transaction launching and is explicitly a partial mitigation, not a substitute for patching. In the same disclosure batch, CVE-2026-27690 affects SAP Approuter, the Node.js-based reverse-proxy/routing middleware fronting SAP Business Technology Platform (BTP) applications in non-Cloud Foundry deployments. An unauthenticated attacker can send a specially crafted HTTP request that triggers request-response desynchronization (HTTP request/response smuggling), allowing exposure of other users' HTTP responses and enabling denial-of-service conditions against the fronted application. CVE-2026-44761 affects SAP Commerce Cloud (formerly Hybris) and stems from a sample OAuth 2.0 client configuration, distributed with publicly documented credentials in SAP Help Portal sample/tutorial material, that was left active in some production deployments. An unauthenticated attacker who obtains these well-known sample credentials can request a valid OAuth access token and invoke Commerce Cloud APIs to read and modify commerce data — customer records, catalogs, pricing, or orders — without ever needing to compromise a real account. Deployments that removed the sample client or rotated its credentials to unique values are not affected. As of disclosure, no vendor, CISA, or open-source reporting indicates in-the-wild exploitation of CVE-2026-44747, CVE-2026-27690, or CVE-2026-44761, and none appears in the CISA Known Exploited Vulnerabilities (KEV) catalog. Given SAP's centrality to finance, supply-chain, HR, and manufacturing operations across nearly every large enterprise and government agency worldwide, and the historical pattern of SAP vulnerabilities being weaponized within weeks of patch disclosure (as seen with prior RECON, ICMAD, and NetWeaver deserialization flaws), rapid patch application and interim ICF hardening are strongly advised even absent confirmed exploitation.
Target sectors: government administration, finance, manufacturing, retail, energy, health, logistics, technology
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-44747, CVE-2026-27690, CVE-2026-44761, T1190, T1078, T1203, T1068, T1211, T1562, T1552, T1528, T1046, T1518