SAP releases 15 security notes, three critical flaws in NetWeaver (heise.de)
0xBASE INTEL BRIEF
- 15 SAP security notes on June 2026 patch day
- Three critical NetWeaver vulnerabilities (CVSS 9.9, 9.8, 9.0)
- CVE-2026-22732: Critical Spring Security flaw in SAP Commerce Cloud
"SAP's June patch day addresses 15 new vulnerabilities, with three critical ones in NetWeaver. The most severe (CVE-2026-44748, CVSS 9.9) allows authenticated attackers to manipulate signed messages. Another (CVE-2026-27671, CVSS 9.8) enables unauthenticated code execution via malformed RFC packets. A Spring Security flaw (CVE-2026-22732, CVSS 9.1) affects SAP Commerce Cloud and Data Hub. Administrators are urged to apply patches promptly."
no comments yet.