Briefing

SAP Releases Security Updates for NetWeaver ABAP, Fixing CVE‑2026‑44747

security
by [email protected] (The Hacker News) · CVE-2026-44747

Patch: apply SAP NetWeaver ABAP update from July 2026 to fix CVE-2026-44747 before exploitation.

What to do now

Patch: apply SAP NetWeaver ABAP update from July 2026, verify integrity, and run vulnerability scan.

Summary

On July 2026, SAP released security updates addressing multiple vulnerabilities, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability, CVE‑2026‑44747, is an out‑of‑bounds write flaw with a CVSS score of 9.9 that allows authenticated attackers to corrupt memory. The flaw exploits logical errors in memory management, potentially leading to arbitrary code execution. SAP's patch for NetWeaver ABAP mitigates the issue by correcting the memory handling routines.

The update also includes fixes for other identified weaknesses across the platform. No active exploitation has been reported yet, but the high severity warrants immediate action. SAP recommends applying the July 2026 security update to all affected systems. Users should verify the patch status and run vulnerability scans to confirm remediation.

Key changes

  • CVE-2026-44747 is an out-of-bounds write flaw in SAP NetWeaver ABAP
  • CVSS score 9.9, allowing authenticated attackers to corrupt memory
  • Exploits logical errors in memory management for arbitrary code execution
  • SAP released July 2026 security update to fix the flaw
  • Update also addresses other identified weaknesses across the platform
  • No active exploitation reported yet
  • High severity warrants immediate action
  • Users should apply the patch and run vulnerability scans

Affects

enterprise

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting