Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical SAP NetWeaver Vulnerabilities Fixed in June Patch

Critical SAP NetWeaver Vulnerabilities Fixed in June Patch

Posted on June 9, 2026 By CWS

In a crucial update, SAP’s June 2026 Security Patch Day, held on June 9, introduced 15 security notes to tackle vulnerabilities across its main product lines. Among these, four critical issues require immediate attention from enterprises to prevent potential security breaches.

The company advises customers to prioritize these patches by accessing the SAP Support Portal, emphasizing swift action to secure their SAP environments.

Key Vulnerabilities in SAP Products

Leading the list of concerns is CVE-2026-44748, a critical XML Signature Wrapping flaw in SAML Authentication impacting SAP NetWeaver AS ABAP and the ABAP Platform, carrying a CVSS score of 9.9. This vulnerability allows low-privileged attackers to exploit signed XML documents, risking unauthorized access and data breaches. This issue affects a broad range of SAP_BASIS versions from 702 to 919.

Another significant vulnerability, CVE-2026-27671 (CVSS 9.8), affects the Application Server ABAP kernel, presenting a memory corruption risk due to improper RFC protocol validation. This flaw is particularly dangerous as it can be exploited without authentication, potentially compromising the confidentiality and availability of systems.

Other Critical Fixes

Another severe issue addressed is CVE-2026-22732 (CVSS 9.1) within SAP Commerce Cloud and SAP Data Hub. This Spring Security vulnerability could allow unauthenticated remote attackers to breach system confidentiality and integrity.

CVE-2026-40128 (CVSS 9.0) highlights a Directory Traversal vulnerability in the SAP NetWeaver Application Server Java Web Container. This flaw could enable attackers to access sensitive resources, posing a high risk to system integrity.

Additional Security Measures and Recommendations

Besides the critical updates, SAP released two high-severity patches. CVE-2026-29145 (CVSS 7.4) addresses Apache Tomcat vulnerabilities in SAP Commerce Cloud, which could be exploited by unauthenticated attackers. CVE-2026-44751 (CVSS 7.1) fixes a Missing Authorization Check in SAP NetWeaver AS ABAP, impacting system integrity.

SAP advises organizations to address these vulnerabilities promptly, prioritizing the most severe flaws to ensure the security of their systems. The company stresses the importance of maintaining a structured patch management process and staying informed about any additional updates.

As the SAP Security Patch Day occurs on the second Tuesday of each month, enterprises are urged to regularly check the SAP Security Notes portal for updates and incorporate these practices into their security strategies.

Cyber Security News Tags:CVE, Java, NetWeaver, RFC, SAML, SAP, SAP Commerce Cloud, SAP Data Hub, security patch, security updates, Vulnerabilities

Post navigation

Previous Post: LiteLLM Vulnerability Enables Remote Code Execution
Next Post: Critical Check Point VPN Flaw Exploited by Ransomware

Related Posts

LG Monitor Software May Install Adware Silently LG Monitor Software May Install Adware Silently Cyber Security News
LangChainGo Vulnerability Let Attackers Access Sensitive Files LangChainGo Vulnerability Let Attackers Access Sensitive Files Cyber Security News
Women’s Dating App Tea Exposes Selfie Images of 13,000 Users Women’s Dating App Tea Exposes Selfie Images of 13,000 Users Cyber Security News
Engineers Charged in Silicon Valley Trade Secrets Case Engineers Charged in Silicon Valley Trade Secrets Case Cyber Security News
Beware of Weaponized ScreenConnect App That Delivers AsyncRAT and PowerShell RAT Beware of Weaponized ScreenConnect App That Delivers AsyncRAT and PowerShell RAT Cyber Security News
Critical TP-Link Router Flaws Threaten Network Security Critical TP-Link Router Flaws Threaten Network Security Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark