Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SAP Addresses Major Vulnerabilities in NetWeaver and Commerce

SAP Addresses Major Vulnerabilities in NetWeaver and Commerce

Posted on June 9, 2026 By CWS

On Tuesday, SAP, a leading provider of enterprise software, issued 15 new security updates, four of which address critical vulnerabilities in NetWeaver, Commerce, and Data Hub systems.

Critical Vulnerabilities in SAP Systems

The most alarming issue resolved is CVE-2026-44748, a critical XML Signature Wrapping vulnerability in the SAML Authentication component of NetWeaver AS ABAP and ABAP Platform, carrying a CVSS score of 9.9. This flaw allows authenticated users with normal privileges to manipulate signed XML documents, potentially gaining unauthorized access to sensitive data, as explained by security firm Onapsis.

To mitigate this risk, temporarily disabling SAML authentication is recommended, as advised by Onapsis. This measure can prevent attackers from exploiting the vulnerability to alter identity information and access critical user data.

Memory Corruption and Directory Traversal Flaws

Another significant flaw, CVE-2026-27671, with a CVSS score of 9.8, involves memory corruption in NetWeaver and ABAP Platform. This problem arises from the SAP kernel’s insufficient validation of the RFC protocol, which allows unauthenticated attackers to exploit logic errors through crafted requests.

Additionally, SAP patched a directory traversal vulnerability, CVE-2026-40128, in NetWeaver Application Server Java, rated at 9.0 on the CVSS scale. This issue permits unauthenticated attackers to manipulate file inclusion parameters through malicious HTTP logon requests, risking sensitive information exposure and potential denial-of-service attacks.

Impact on Commerce Cloud and Data Hub

The third critical vulnerability, CVE-2026-22732, affects Commerce Cloud and Data Hub, with a CVSS score of 9.1. This weakness impacts applications using the Spring Security framework when specifying HTTP response headers, potentially leading to unrecorded HTTP headers, as highlighted by a NIST advisory.

In addition to these critical patches, SAP addressed high-severity vulnerabilities in Apache Tomcat used in Commerce Cloud and a missing authorization check in NetWeaver and ABAP Platform, enhancing security across its product suite.

These updates underscore SAP’s commitment to maintaining robust security measures in its software, ensuring customers remain protected against emerging threats.

Security Week News Tags:Commerce, Cybersecurity, memory corruption, NetWeaver, Patches, SAML Authentication, SAP, Security, Vulnerabilities, XML Signature Wrapping

Post navigation

Previous Post: Cyber Attacks Exploit WinRAR Flaw Against Ukraine
Next Post: Weedhack Malware Poses Threat to Minecraft Users

Related Posts

Cybercriminals Trade 183 Million Stolen Credentials on Telegram, Dark Forums Cybercriminals Trade 183 Million Stolen Credentials on Telegram, Dark Forums Security Week News
RSAC 2026: Key Highlights from Days 3-4 RSAC 2026: Key Highlights from Days 3-4 Security Week News
CISA Warns of Attacks Exploiting N-able Vulnerabilities CISA Warns of Attacks Exploiting N-able Vulnerabilities Security Week News
Google Chrome 146 Update Fixes Critical Security Flaws Google Chrome 146 Update Fixes Critical Security Flaws Security Week News
US Experts Jailed for Ransomware Conspiracy Involvement US Experts Jailed for Ransomware Conspiracy Involvement Security Week News
China Accuses US of Cyberattack on National Time Center China Accuses US of Cyberattack on National Time Center Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cryptographic Invisibility Revolutionizes AI App Security
  • AI-Driven Worm Revolutionizes Cybersecurity Threats
  • Weedhack Malware Poses Threat to Minecraft Users
  • SAP Addresses Major Vulnerabilities in NetWeaver and Commerce
  • Cyber Attacks Exploit WinRAR Flaw Against Ukraine

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cryptographic Invisibility Revolutionizes AI App Security
  • AI-Driven Worm Revolutionizes Cybersecurity Threats
  • Weedhack Malware Poses Threat to Minecraft Users
  • SAP Addresses Major Vulnerabilities in NetWeaver and Commerce
  • Cyber Attacks Exploit WinRAR Flaw Against Ukraine

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark