CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0230 [1.01] [M/H] Vulnerabilities fixed in SAP products

unknownCVE-2026-44747CVE-2026-27690CVE-2026-44761CVE-2026-40128CVE-2026-40860CVE-2026-0487
SAP has fixed vulnerabilities in SAP NetWeaver Application Server ABAP, SAP Approuter, SAP Commerce Cloud, SAP NetWeaver Application Server Java, SAProuter, SAP Change and Transport System Attach Tool, SAP NetWeaver Enterprise Portal, SAP S/4HANA modules, SAP Fiori Launchpad, SAP CRM WebClient UI, SAP HANA Database user self service tools, and SAP Commerce Cloud. Update: Due to a processing error, no references were provided. This has been corrected. There are no further substantive changes. The vulnerabilities involve various security issues such as: - memory corruption in SAP NetWeaver Application Server ABAP - HTTP Request Smuggling in SAP Approuter - insecure OAuth2 sample credentials in SAP Commerce Cloud - directory traversal in SAP NetWeaver Application Server Java - DLL hijacking in SAProuter on Windows. - Additionally, there are Cross-Site Scripting (XSS) vulnerabilities in SAP NetWeaver Application Server Java and Enterprise Portal and missing authorization controls in SAP S/4HANA modules. - SAP Change and Transport System Attach Tool is vulnerable to remote code execution due to insecure deserialization. - SAP HANA user self service tools allow information transfer without authentication. The vulnerabilities can lead to unauthorized access, data manipulation, information leaks, and disruption of availability. Some vulnerabilities require authentication, while others can be exploited by unauthorized users. Various vulnerabilities are specific to components used within SAP environments, such as Apache Camel within the SAP Integration Suite and Apache Tomcat within SAP Commerce Cloud.

CSIRTS triage

What
SAP has fixed various vulnerabilities including memory corruption and HTTP request smuggling.
Who is affected
Users of various SAP products are affected.
Urgency
Remediation is important as vulnerabilities could lead to significant security issues.
Action
Update all affected SAP products to the latest versions.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch SAP products

Get an email when a new SAP products advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-07-17
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0230

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-44747coverage & exploitation statusNVD · CVE.org
CVE-2026-27690coverage & exploitation statusNVD · CVE.org
CVE-2026-44761coverage & exploitation statusNVD · CVE.org
CVE-2026-40128coverage & exploitation statusNVD · CVE.org
CVE-2026-40860coverage & exploitation statusNVD · CVE.org
CVE-2026-0487coverage & exploitation statusNVD · CVE.org
CVE-2026-44752coverage & exploitation statusNVD · CVE.org
CVE-2026-44745coverage & exploitation statusNVD · CVE.org
CVE-2026-43512coverage & exploitation statusNVD · CVE.org
CVE-2026-41293coverage & exploitation statusNVD · CVE.org
CVE-2026-43515coverage & exploitation statusNVD · CVE.org
CVE-2026-58233coverage & exploitation statusNVD · CVE.org
CVE-2026-44759coverage & exploitation statusNVD · CVE.org
CVE-2026-44767coverage & exploitation statusNVD · CVE.org
CVE-2026-44769coverage & exploitation statusNVD · CVE.org
CVE-2026-44760coverage & exploitation statusNVD · CVE.org
CVE-2026-44771coverage & exploitation statusNVD · CVE.org
CVE-2026-44770coverage & exploitation statusNVD · CVE.org
CVE-2026-24315coverage & exploitation statusNVD · CVE.org
CVE-2026-44768coverage & exploitation statusNVD · CVE.org
CVE-2026-44753coverage & exploitation statusNVD · CVE.org
CVE-2025-68161coverage & exploitation statusNVD · CVE.org
CVE-2026-40453coverage & exploitation statusNVD · CVE.org
CVE-2025-27636coverage & exploitation statusNVD · CVE.org
CVE-2026-33454coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from NCSC-NL Advisories