cbcvebase.
CVE-2026-44747
published 2026-07-14

CVE-2026-44747: SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could…

PriorityP261critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.53%
41.8th percentile
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application.

Affected

13 ranges
VendorProductVersion rangeFixed in
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap

Detection & IOCsextracted from sources · hover to see the quote

  • Temporary workaround: disable all ICF nodes with a specific property in transaction SICF to mitigate CVE-2026-44747 exploitation surface
  • For CVE-2026-44761 (SAP Commerce Cloud), audit production environments for the presence of the affected sample OAuth 2.0 client configured with hard-coded, well-known credentials from SAP Help Portal sample scripts
  • CVE-2026-44761: Exploitation requires that the customer executed the sample script and retained the resulting OAuth 2.0 client in production without replacing the hard-coded secret; presence of the default OAuth 2.0 client is a direct indicator of exposure
  • ·CVE-2026-44747 workaround (disabling ICF nodes via SICF) will disable opening transactions in SAP GUI for HTML and is therefore not viable for all customers; patching the ABAP Kernel is strongly recommended instead
  • ·CVE-2026-44761 only affects SAP Commerce Cloud deployments where the sample OAuth 2.0 client from SAP Help Portal documentation was imported into production and the hard-coded secret was not replaced; customers who removed the client or replaced the secret are not impacted
  • ·CVE-2026-27690 affects SAP Approuter deployments specifically in non-Cloud Foundry environments; Cloud Foundry deployments are not referenced as affected
  • ·No evidence of any of the three CVEs being exploited in the wild as of the July 2026 SAP patch release
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.