NCSC-2026-0230 [1.01] [M/H] Vulnerabilities fixed in SAP products
SAP has fixed vulnerabilities in SAP NetWeaver Application Server ABAP, SAP Approuter, SAP Commerce Cloud, SAP NetWeaver Application Server Java, SAProuter, SAP Change and Transport System Attach Tool, SAP NetWeaver Enterprise Portal, SAP S/4HANA modules, SAP Fiori Launchpad, SAP CRM WebClient UI, SAP HANA Database user self service tools, and SAP Commerce Cloud. Update: Due to a processing error, no references were provided. This has been corrected. There are no further substantive changes. The vulnerabilities involve various security issues such as: - memory corruption in SAP NetWeaver Application Server ABAP - HTTP Request Smuggling in SAP Approuter - insecure OAuth2 sample credentials in SAP Commerce Cloud - directory traversal in SAP NetWeaver Application Server Java - DLL hijacking in SAProuter on Windows. - Additionally, there are Cross-Site Scripting (XSS) vulnerabilities in SAP NetWeaver Application Server Java and Enterprise Portal and missing authorization controls in SAP S/4HANA modules. - SAP Change and Transport System Attach Tool is vulnerable to remote code execution due to insecure deserialization. - SAP HANA user self service tools allow information transfer without authentication. The vulnerabilities can lead to unauthorized access, data manipulation, information leaks, and disruption of availability. Some vulnerabilities require authentication, while others can be exploited by unauthorized users. Various vulnerabilities are specific to components used within SAP environments, such as Apache Camel within the SAP Integration Suite and Apache Tomcat within SAP Commerce Cloud.
CSIRTS triage
- What
- SAP has fixed various vulnerabilities including memory corruption and HTTP request smuggling.
- Who is affected
- Users of various SAP products are affected.
- Urgency
- Remediation is important as vulnerabilities could lead to significant security issues.
- Action
- Update all affected SAP products to the latest versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch SAP products
Get an email when a new SAP products advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0230
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-447470.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all scored CVEs.
- Low exploitation riskCVE-2026-276900.69% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all scored CVEs.
- Low exploitation riskCVE-2026-447610.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Low exploitation riskCVE-2026-401280.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all scored CVEs.
- Moderate exploitation riskCVE-2026-408601.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 66% of all scored CVEs.
- Low exploitation riskCVE-2026-04870.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all scored CVEs.
- Low exploitation riskCVE-2026-447520.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-447450.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all scored CVEs.
- Moderate exploitation riskCVE-2026-435121.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 66% of all scored CVEs.
- Moderate exploitation riskCVE-2026-412931.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 73% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- low[UPDATE] [low] Apache log4j: Vulnerability allows information disclosurecert-bund
- high[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: …cert-bund
- high[NEW] [high] SAP Patch Day July 2026cert-bund
- high[NEW] [high] Oracle Solaris third-party components: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Apache Tomcat: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Oracle Weblogic (July 23, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Oracle MySQL (July 23, 2026)cert-fr-avis
- unknownNCSC-2026-0257 [1.00] [M/H] Vulnerabilities fixed in Oracle Enterprise Managerncsc-nl
- high[NEW] [high] Oracle Supply Chain: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Enterprise Manager: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Commerce: Multiple vulnerabilitiescert-bund
- unknownUSN-8551-1: Tomcat vulnerabilitiesubuntu
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30