discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

SAP fixes critical flaws in NetWeaver and Commerce Cloud

SAP patched 15 vulnerabilities in its June 2026 update, including four critical flaws in NetWeaver and Commerce Cloud. The issues include auth bypass, memory corruption, and directory traversal bugs.

By Bill Toulas·Jun 9·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

SAP fixes critical flaws in NetWeaver and Commerce Cloud
Image: bleepingcomputer.com

SAP’s June 2026 Security Patch package closes 15 vulnerabilities across multiple products, with the most urgent fixes landing in NetWeaver and Commerce Cloud. The headline risks include a SAML authentication bypass path, a memory corruption issue reachable without authentication, and other high-severity bugs.

Why it matters

These products sit at the center of enterprise identity, application serving, and commerce workflows, so flaws here can have broad impact. The critical issues could let attackers bypass authentication, tamper with sensitive data, or disrupt systems if left unpatched.

SAP found serious holes in the software many companies use to run their systems and online stores. It patched them like fixing weak locks on important doors, because attackers could use those holes to sneak in or mess things up.

Analysis

What SAP fixed

SAP says its June 2026 Security Patch package addresses 15 vulnerabilities in total, including four critical-severity flaws. The most serious issues affect SAP NetWeaver and SAP Commerce Cloud, both widely used in enterprise environments.

The critical issues

One critical bug, CVE-2026-44748, affects SAP NetWeaver AS ABAP and ABAP Platform. SAP describes it as an XML Signature Wrapping problem that could allow authentication bypass in SAML-based environments. In practice, that means an attacker could potentially tamper with identity data and get a system to accept it as valid.

CVE-2026-27671 is a memory corruption flaw in SAP NetWeaver/ABAP Platform Application Server ABAP. SAP says it can be exploited without authentication by sending crafted RFC requests to vulnerable endpoints, with improper kernel validation leading to memory corruption.

The other critical issues are CVE-2026-22732, a Spring Security-related flaw affecting SAP Commerce Cloud and SAP Data Hub, and CVE-2026-40128, a directory traversal issue in SAP NetWeaver Application Server Java’s Web Container.

Broader patch set

SAP also fixed two high-severity issues: CVE-2026-29145, which involves multiple Apache Tomcat flaws in Commerce Cloud, and CVE-2026-44751, a missing authorization check in NetWeaver AS ABAP. Beyond that, the bulletin includes SQL injection, path traversal, cross-site scripting, email spoofing, and authorization bypass fixes across other SAP products.

SAP says detailed mitigation advice and workarounds are available only to customers with a security portal account. The article urges organizations to prioritize the SAML-related flaw and the memory corruption bug because of their high severity and potential enterprise impact.

Key points

  • SAP released fixes for 15 vulnerabilities in its June 2026 Security Patch package.
  • Four critical flaws affect SAP NetWeaver and SAP Commerce Cloud.
  • CVE-2026-44748 could allow authentication bypass in SAML-based environments.
  • CVE-2026-27671 can reportedly be triggered without authentication through crafted RFC requests.
  • SAP also fixed two high-severity issues and several lower-severity bugs across other products.
The Upside

If organizations patch quickly, the most dangerous paths into NetWeaver and Commerce Cloud can be closed before attackers take advantage of them. The fixes also reduce exposure across related SAP products where similar bugs were found.

The Downside

If patching is delayed, the authentication bypass and memory corruption issues could expose sensitive data or disrupt normal system use. Enterprises running these SAP products may also face risk from the additional high-severity and lower-severity flaws if they are left unaddressed.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritytechbusinessenterprise-software

Author

Bill Toulas

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 9, 2026

Source

bleepingcomputer.com

Share

Topics

securitytechbusinessenterprise-software

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…