SAP July 2026 fixes critical NetWeaver ABAP flaw
🔒 SAP released its July 2026 security updates to remediate multiple serious vulnerabilities, including a critical NetWeaver Application Server ABAP out-of-bounds write (CVE-2026-44747). Vendors and customers are urged to apply the ABAP Kernel patch because the suggested workaround—disabling specific ICF nodes via SICF—may break SAP GUI for HTML. Other addressed issues include an HTTP request/response smuggling bug in Approuter (CVE-2026-27690) and a default-credential OAuth client issue in Commerce Cloud (CVE-2026-44761). SAP notes no evidence of active exploitation but recommends immediate patching and auditing of production instances for sample OAuth clients.
