CVE-2026-44747
published 2026-07-14CVE-2026-44747: SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could…
PriorityP261critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.53%
41.8th percentile
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Temporary workaround: disable all ICF nodes with a specific property in transaction SICF to mitigate CVE-2026-44747 exploitation surface ↗
- →For CVE-2026-44761 (SAP Commerce Cloud), audit production environments for the presence of the affected sample OAuth 2.0 client configured with hard-coded, well-known credentials from SAP Help Portal sample scripts ↗
- →CVE-2026-44761: Exploitation requires that the customer executed the sample script and retained the resulting OAuth 2.0 client in production without replacing the hard-coded secret; presence of the default OAuth 2.0 client is a direct indicator of exposure ↗
- ·CVE-2026-44747 workaround (disabling ICF nodes via SICF) will disable opening transactions in SAP GUI for HTML and is therefore not viable for all customers; patching the ABAP Kernel is strongly recommended instead ↗
- ·CVE-2026-44761 only affects SAP Commerce Cloud deployments where the sample OAuth 2.0 client from SAP Help Portal documentation was imported into production and the hard-coded secret was not replaced; customers who removed the client or replaced the secret are not impacted ↗
- ·CVE-2026-27690 affects SAP Approuter deployments specifically in non-Cloud Foundry environments; Cloud Foundry deployments are not referenced as affected ↗
- ·No evidence of any of the three CVEs being exploited in the wild as of the July 2026 SAP patch release ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
blogs_hackernews·2026-07-20·CVSS 5.9
CVE-2026-63030 [MEDIUM] ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.
The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.
Here is the full recap of what broke, what was exploited, and what needs attention now.
## ⚡ Threat of the Week
New wp2shell WordPress Core Flaw Lets Unauthe
Hackernews
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
blogs_hackernews·2026-07-14·CVSS 9.1
CVE-2026-44747 [CRITICAL] SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP.
The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds write flaw that allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability.
"As a temporary workaround the note proposes to disable all ICF nodes with a specific pr
2026-07-14
Published