CVE-2026-44747: Critical Memory Corruption in SAP NetWeaver Application Server ABAP (CVSS 9.9) — Threadlinqs Intelligence
As of 2026-07-17, CVE-2026-44747: Critical Memory Corruption in SAP NetWeaver Application Server ABAP (CVSS 9.9) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-1438 · Severity: CRITICAL · CVSS: 9.9 · Status: PATCHED · Category: VULNERABILITY
SAP's July 2026 Security Patch Day fixed CVE-2026-44747, a CVSS 9.9 out-of-bounds write (CWE-787) in the SAP NetWeaver Application Server ABAP kernel, where an authenticated attacker with only low
CVE-2026-44747 is a critical out-of-bounds write vulnerability (CWE-787) in the kernel of SAP NetWeaver Application Server ABAP (AS ABAP), the core runtime, application server, and development platform underlying the majority of SAP's on-premise ERP, S/4HANA, and custom ABAP-based enterprise deployments. The flaw is rooted in logical errors within the kernel's memory-management routines: an authenticated attacker holding only low privileges can send crafted requests or invoke specific kernel-level functionality that causes the kernel to write data outside the bounds of an allocated buffer or object. Because the corrupted memory lives inside the privileged application-server process space, the resulting corruption can be leveraged to alter program execution flow, read or modify data the attacker should not have access to, or crash the kernel process outright, producing a denial of service for the affected SAP instance.
The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) reflects a network-reachable vulnerability with low attack complexity, requiring only low privileges and no user interaction, with a scope change (S:C) indicating the impact extends beyond the vulnerable component's own security authority into other components of the SAP landscape — consistent with kernel-level memory corruption in a multi-tenant enterprise application server. Full compromise yields high impact to confidentiality, integrity, and availability simultaneously, which is why the score sits at the top of the critical band (9.9).
The vulnerability spans an unusually broad kernel version matrix — KRNL64NUC 7.22/7.22EXT, KRNL64UC 7.22/7.22EXT/7.53, and KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19, and 9.20 — meaning it affects both legacy Non-Unicode kernel branches still running in older NetWeaver landscapes and the current 9.x kernel lines used by modern S/4HANA and NetWeaver AS ABAP installations, making the exposure relevant to nearly every AS ABAP customer regardless of upgrade cadence.
SAP's primary remediation is deployment of a corrected ABAP kernel patch level per Security Note 3747367. Onapsis, credited with contributing to discovery/response, documented a temporary compensating control: disabling specific ICF (Internet Communication Framework) nodes via transaction SICF that expose the vulnerable functionality. This workaround is explicitly a stopgap — SAP and Onapsis both note it interrupts SAP GUI for HTML (WebGUI) workflows for affected users and is not viable for all customer landscapes, so kernel patching remains the recommended fix.
The fix shipped as part of a broader July 2026 SAP Patch Day releasing 16 new security notes plus one GitHub security advisory and three updates to prior notes, including two other critical (CVSS ≥9.0) issues disclosed the same day: CVE-2026-27690 (CVSS 9.1, unauthenticated HTTP request/response smuggling in the Node.js-based SAP Approuter used by non-Cloud-Foundry BTP applications, enabling response hijacking and DoS) and CVE-2026-44761 (CVSS 9.1, a hard-coded/default sample OAuth 2.0 client credential shipped in SAP Commerce Cloud documentation, letting an unauthenticated attacker mint valid access tokens and read/modify Commerce Cloud data via its APIs). A fourth high-severity SAP AS Java Web Container directory-traversal flaw (CVE-2026-40128, CVSS 9.0) allowing unauthorized file access/modification was reported alongside these in patch-day coverage.
No evidence of in-the-wild exploitation or a public proof-of-concept exists for CVE-2026-44747 as of disclosure, and it has not (yet) been added to the CISA Known Exploited Vulnerabilities catalog. However, SAP vulnerabilities are a persistent, high-value target for ransomware affiliates and espionage actors: CISA has added 14 separate SAP flaws to KEV since November 2021, including at least two subsequently weaponized by ransomware operators, underscoring that the historical time-to-exploitation for critical SAP kernel/NetWeaver bugs
Target sectors: government administration, manufacturing, finance, energy, retail, critical-infrastructure, supply-chain
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-44747, CVE-2026-27690, CVE-2026-44761, CVE-2026-40128, T1190, T1078, T1203, T1505, T1068, T1211, T1070, T1078, T1552, T1518