Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical SAP NetWeaver Vulnerabilities Fixed in June Patch

Critical SAP NetWeaver Vulnerabilities Fixed in June Patch

Posted on June 9, 2026 By CWS

In a crucial update, SAP’s June 2026 Security Patch Day, held on June 9, introduced 15 security notes to tackle vulnerabilities across its main product lines. Among these, four critical issues require immediate attention from enterprises to prevent potential security breaches.

The company advises customers to prioritize these patches by accessing the SAP Support Portal, emphasizing swift action to secure their SAP environments.

Key Vulnerabilities in SAP Products

Leading the list of concerns is CVE-2026-44748, a critical XML Signature Wrapping flaw in SAML Authentication impacting SAP NetWeaver AS ABAP and the ABAP Platform, carrying a CVSS score of 9.9. This vulnerability allows low-privileged attackers to exploit signed XML documents, risking unauthorized access and data breaches. This issue affects a broad range of SAP_BASIS versions from 702 to 919.

Another significant vulnerability, CVE-2026-27671 (CVSS 9.8), affects the Application Server ABAP kernel, presenting a memory corruption risk due to improper RFC protocol validation. This flaw is particularly dangerous as it can be exploited without authentication, potentially compromising the confidentiality and availability of systems.

Other Critical Fixes

Another severe issue addressed is CVE-2026-22732 (CVSS 9.1) within SAP Commerce Cloud and SAP Data Hub. This Spring Security vulnerability could allow unauthenticated remote attackers to breach system confidentiality and integrity.

CVE-2026-40128 (CVSS 9.0) highlights a Directory Traversal vulnerability in the SAP NetWeaver Application Server Java Web Container. This flaw could enable attackers to access sensitive resources, posing a high risk to system integrity.

Additional Security Measures and Recommendations

Besides the critical updates, SAP released two high-severity patches. CVE-2026-29145 (CVSS 7.4) addresses Apache Tomcat vulnerabilities in SAP Commerce Cloud, which could be exploited by unauthenticated attackers. CVE-2026-44751 (CVSS 7.1) fixes a Missing Authorization Check in SAP NetWeaver AS ABAP, impacting system integrity.

SAP advises organizations to address these vulnerabilities promptly, prioritizing the most severe flaws to ensure the security of their systems. The company stresses the importance of maintaining a structured patch management process and staying informed about any additional updates.

As the SAP Security Patch Day occurs on the second Tuesday of each month, enterprises are urged to regularly check the SAP Security Notes portal for updates and incorporate these practices into their security strategies.

Cyber Security News Tags:CVE, Java, NetWeaver, RFC, SAML, SAP, SAP Commerce Cloud, SAP Data Hub, security patch, security updates, Vulnerabilities

Post navigation

Previous Post: LiteLLM Vulnerability Enables Remote Code Execution
Next Post: Critical Check Point VPN Flaw Exploited by Ransomware

Related Posts

12 Best Infrastructure Monitoring Tools in 2025 12 Best Infrastructure Monitoring Tools in 2025 Cyber Security News
Silver Fox Shifts Tactics to Python-Based Threats in Asia Silver Fox Shifts Tactics to Python-Based Threats in Asia Cyber Security News
Gunra Ransomware Expands Global RaaS Operations Gunra Ransomware Expands Global RaaS Operations Cyber Security News
Adobe Data Breach: 13 Million Records Allegedly Leaked Adobe Data Breach: 13 Million Records Allegedly Leaked Cyber Security News
BlackSuit Ransomware’s Data Leak and Negotiation Portal Seized BlackSuit Ransomware’s Data Leak and Negotiation Portal Seized Cyber Security News
Critical Vulnerability in TP-Link Routers Exposed Critical Vulnerability in TP-Link Routers Exposed Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SAP Addresses Major Vulnerabilities in NetWeaver and Commerce
  • Cyber Attacks Exploit WinRAR Flaw Against Ukraine
  • Phishing Scams Exploit AI Tool Brands for Credential Theft
  • Shai-Hulud Supply Chain Attacks Target NPM and PyPI Packages
  • Unveiling the Hidden Risks in Network Security Operations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SAP Addresses Major Vulnerabilities in NetWeaver and Commerce
  • Cyber Attacks Exploit WinRAR Flaw Against Ukraine
  • Phishing Scams Exploit AI Tool Brands for Credential Theft
  • Shai-Hulud Supply Chain Attacks Target NPM and PyPI Packages
  • Unveiling the Hidden Risks in Network Security Operations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark