CVE-2026-27690
published 2026-07-14CVE-2026-27690: Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to…
PriorityP260critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.68%
50.0th percentile
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap_se | sap_approuter | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target: SAP Approuter deployments in non-Cloud Foundry environments are specifically affected by this HTTP request smuggling vulnerability ↗
- →Attack vector: Unauthenticated attacker sends a specially crafted HTTP request causing request-response desynchronization; monitor for malformed/ambiguous HTTP requests (e.g., conflicting Content-Length and Transfer-Encoding headers) directed at SAP Approuter endpoints ↗
- →Impact indicators: Successful exploitation results in exposure of other users' HTTP responses and denial-of-service; monitor for unexpected response body leakage or service unavailability on SAP Approuter instances ↗
- ·Vulnerability is specific to SAP Approuter deployments in non-Cloud Foundry environments; Cloud Foundry-based deployments are not mentioned as affected ↗
- ·No evidence of in-the-wild exploitation reported at time of disclosure; patching is the recommended remediation ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SAP Approuter HTTP request smuggling
vuldb·2026-07-14·CVSS 9.1
CVE-2026-27690 [CRITICAL] SAP Approuter HTTP request smuggling
A vulnerability labeled as problematic has been found in SAP Approuter. The impacted element is an unknown function of the component HTTP Handler. Executing a manipulation can lead to http request smuggling.
This vulnerability is registered as CVE-2026-27690. It is possible to launch the attack remotely. No exploit is available.
GHSA
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization.
ghsa_unreviewed·2026-07-14
CVE-2026-27690 [CRITICAL] CWE-444 Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization.
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
blogs_hackernews·2026-07-20·CVSS 5.9
CVE-2026-63030 [MEDIUM] ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.
The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.
Here is the full recap of what broke, what was exploited, and what needs attention now.
## ⚡ Threat of the Week
New wp2shell WordPress Core Flaw Lets Unauthe
Hackernews
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
blogs_hackernews·2026-07-14·CVSS 9.1
CVE-2026-44747 [CRITICAL] SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP.
The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds write flaw that allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability.
"As a temporary workaround the note proposes to disable all ICF nodes with a specific pr
2026-07-14
Published