Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SAP Addresses Major Vulnerabilities in NetWeaver and Commerce

SAP Addresses Major Vulnerabilities in NetWeaver and Commerce

Posted on June 9, 2026 By CWS

On Tuesday, SAP, a leading provider of enterprise software, issued 15 new security updates, four of which address critical vulnerabilities in NetWeaver, Commerce, and Data Hub systems.

Critical Vulnerabilities in SAP Systems

The most alarming issue resolved is CVE-2026-44748, a critical XML Signature Wrapping vulnerability in the SAML Authentication component of NetWeaver AS ABAP and ABAP Platform, carrying a CVSS score of 9.9. This flaw allows authenticated users with normal privileges to manipulate signed XML documents, potentially gaining unauthorized access to sensitive data, as explained by security firm Onapsis.

To mitigate this risk, temporarily disabling SAML authentication is recommended, as advised by Onapsis. This measure can prevent attackers from exploiting the vulnerability to alter identity information and access critical user data.

Memory Corruption and Directory Traversal Flaws

Another significant flaw, CVE-2026-27671, with a CVSS score of 9.8, involves memory corruption in NetWeaver and ABAP Platform. This problem arises from the SAP kernel’s insufficient validation of the RFC protocol, which allows unauthenticated attackers to exploit logic errors through crafted requests.

Additionally, SAP patched a directory traversal vulnerability, CVE-2026-40128, in NetWeaver Application Server Java, rated at 9.0 on the CVSS scale. This issue permits unauthenticated attackers to manipulate file inclusion parameters through malicious HTTP logon requests, risking sensitive information exposure and potential denial-of-service attacks.

Impact on Commerce Cloud and Data Hub

The third critical vulnerability, CVE-2026-22732, affects Commerce Cloud and Data Hub, with a CVSS score of 9.1. This weakness impacts applications using the Spring Security framework when specifying HTTP response headers, potentially leading to unrecorded HTTP headers, as highlighted by a NIST advisory.

In addition to these critical patches, SAP addressed high-severity vulnerabilities in Apache Tomcat used in Commerce Cloud and a missing authorization check in NetWeaver and ABAP Platform, enhancing security across its product suite.

These updates underscore SAP’s commitment to maintaining robust security measures in its software, ensuring customers remain protected against emerging threats.

Security Week News Tags:Commerce, Cybersecurity, memory corruption, NetWeaver, Patches, SAML Authentication, SAP, Security, Vulnerabilities, XML Signature Wrapping

Post navigation

Previous Post: Cyber Attacks Exploit WinRAR Flaw Against Ukraine
Next Post: Weedhack Malware Poses Threat to Minecraft Users

Related Posts

Palo Alto Networks to Acquire Koi for Enhanced AI Security Palo Alto Networks to Acquire Koi for Enhanced AI Security Security Week News
The Cybersecurity Information Sharing Act Faces Expiration The Cybersecurity Information Sharing Act Faces Expiration Security Week News
Anubis Ransomware Packs a Wiper to Permanently Delete Files Anubis Ransomware Packs a Wiper to Permanently Delete Files Security Week News
Oracle Responds to PeopleSoft Security Threat Amid Hacker Attacks Oracle Responds to PeopleSoft Security Threat Amid Hacker Attacks Security Week News
Agentic Security Firm 7AI Raises 0 Million Agentic Security Firm 7AI Raises $130 Million Security Week News
Jscrambler Packages Compromised in Supply Chain Breach Jscrambler Packages Compromised in Supply Chain Breach Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark