SAP fixes critical flaws in NetWeaver and Commerce Cloud
SAP patched 15 vulnerabilities in its June 2026 update, including four critical flaws in NetWeaver and Commerce Cloud. The issues include auth bypass, memory corruption, and directory traversal bugs.
Intelligence analysis by GPT-5.4 Mini

SAP’s June 2026 Security Patch package closes 15 vulnerabilities across multiple products, with the most urgent fixes landing in NetWeaver and Commerce Cloud. The headline risks include a SAML authentication bypass path, a memory corruption issue reachable without authentication, and other high-severity bugs.
SAP found serious holes in the software many companies use to run their systems and online stores. It patched them like fixing weak locks on important doors, because attackers could use those holes to sneak in or mess things up.
Analysis
What SAP fixed
SAP says its June 2026 Security Patch package addresses 15 vulnerabilities in total, including four critical-severity flaws. The most serious issues affect SAP NetWeaver and SAP Commerce Cloud, both widely used in enterprise environments.
The critical issues
One critical bug, CVE-2026-44748, affects SAP NetWeaver AS ABAP and ABAP Platform. SAP describes it as an XML Signature Wrapping problem that could allow authentication bypass in SAML-based environments. In practice, that means an attacker could potentially tamper with identity data and get a system to accept it as valid.
CVE-2026-27671 is a memory corruption flaw in SAP NetWeaver/ABAP Platform Application Server ABAP. SAP says it can be exploited without authentication by sending crafted RFC requests to vulnerable endpoints, with improper kernel validation leading to memory corruption.
The other critical issues are CVE-2026-22732, a Spring Security-related flaw affecting SAP Commerce Cloud and SAP Data Hub, and CVE-2026-40128, a directory traversal issue in SAP NetWeaver Application Server Java’s Web Container.
Broader patch set
SAP also fixed two high-severity issues: CVE-2026-29145, which involves multiple Apache Tomcat flaws in Commerce Cloud, and CVE-2026-44751, a missing authorization check in NetWeaver AS ABAP. Beyond that, the bulletin includes SQL injection, path traversal, cross-site scripting, email spoofing, and authorization bypass fixes across other SAP products.
SAP says detailed mitigation advice and workarounds are available only to customers with a security portal account. The article urges organizations to prioritize the SAML-related flaw and the memory corruption bug because of their high severity and potential enterprise impact.
Key points
- SAP released fixes for 15 vulnerabilities in its June 2026 Security Patch package.
- Four critical flaws affect SAP NetWeaver and SAP Commerce Cloud.
- CVE-2026-44748 could allow authentication bypass in SAML-based environments.
- CVE-2026-27671 can reportedly be triggered without authentication through crafted RFC requests.
- SAP also fixed two high-severity issues and several lower-severity bugs across other products.
If organizations patch quickly, the most dangerous paths into NetWeaver and Commerce Cloud can be closed before attackers take advantage of them. The fixes also reduce exposure across related SAP products where similar bugs were found.
If patching is delayed, the authentication bypass and memory corruption issues could expose sensitive data or disrupt normal system use. Enterprises running these SAP products may also face risk from the additional high-severity and lower-severity flaws if they are left unaddressed.



