SAP kicked off its July 2026 Security Patch Day with a lineup that demands immediate attention from enterprise security teams. Released on July 14, the update includes 16 new security notes and 1 GitHub security advisory, alongside 3 revisions to previously issued notes.
The headline vulnerability, a maximum-severity memory corruption flaw in SAP NetWeaver Application Server ABAP, earns a near-perfect CVSS score of 9.9, making it the month’s most urgent fix.
With three critical-severity notes and a broad spread of high and medium-severity issues touching everything from SAP Commerce Cloud to the Approuter Node.js package, this patch cycle underscores just how sprawling the modern SAP attack surface has become.
SAP Security Patch Day July 2026
Three vulnerabilities carry critical ratings this month, and each targets a different layer of the SAP stack:
- CVE-2026-44747 (CVSS 9.9): A memory corruption vulnerability in SAP NetWeaver AS ABAP affects multiple kernel versions (7.22 through 9.20), creating the potential for remote code execution via a network-based attack vector and low privilege requirements.
- CVE-2026-27690 (CVSS 9.1): An HTTP request smuggling flaw in the SAP Approuter Node.js package (versions below 20.10.0) could let attackers manipulate request routing, a particularly dangerous issue for cloud-fronting components.
- CVE-2026-44761 (CVSS 9.1): Insecure sample credentials shipped in SAP Commerce Cloud (HY_COM 2205, COM_CLOUD 2211) are a stark reminder that default or sample credentials remain a persistent, avoidable risk in enterprise software.
Several high-severity notes round out the list, including a DLL hijacking bug in SAProuter on Windows (CVE-2026-0487, CVSS 8.4), multiple Apache Camel vulnerabilities inside SAP Integration Suite’s Edge Integration Cell (CVE-2026-40860 and related CVEs, CVSS 8.8), and a cluster of Apache Tomcat flaws bundled into SAP Commerce Cloud (CVSS 8.1).
A remote code execution flaw in the Change and Transport System Attach Tool (CVE-2026-58233, CVSS 7.6) also deserves attention from teams managing transport landscapes.
Notably, several of this month’s notes trace back to third-party dependencies embedded in SAP products: Apache Camel, Apache Tomcat, and the UI5 webcomponents-base library (CVE-2026-44767, addressed via GitHub advisory GHSA-p8gx-753q-v89p).
This pattern reflects a broader industry trend: as enterprise software increasingly relies on open-source components, vulnerability management can no longer stop at vendor-issued code. Security teams must track upstream CVEs affecting bundled libraries just as closely as SAP-native flaws.
SAP also revised three June 2026 notes, covering a directory traversal flaw in NetWeaver AS Java’s Web Container (CVE-2026-40128, now critical at CVSS 9.0), a path traversal issue in SAP Fiori launchpad (CVE-2026-24315), and an Apache Log4j-related note for NetWeaver AS Java (CVE-2025-68161).
Revisions typically indicate expanded affected version ranges or refined remediation guidance, so rechecking applicability is essential even if the original note has already been actioned.
What Security Teams Should Do Next
- Prioritize patching the 9.9- and 9.1-rated critical notes within days, not weeks, especially on internet-facing NetWeaver and Commerce Cloud instances.
- Audit Approuter deployments for outdated Node.js package versions.
- Review Apache Camel, Tomcat, and Log4j versions bundled within SAP Integration Suite and Commerce Cloud environments.
- Rotate or disable any sample credentials shipped with Commerce Cloud installations.
- Cross-reference SAP’s credits page to understand which research firms flagged which issues, useful context for threat modeling.
SAP customers should treat this patch day as a priority cycle, given the presence of a near-maximum-severity CVE. As always, the full technical details and downloadable patches are available through the SAP Support Portal.