Critical SAP Vulnerabilities: ABAP, Approuter and Commerce Cloud Need Review

Colleagues, I’d like to highlight key cybersecurity updates.
SAP has fixed critical CVE-2026-44747 in NetWeaver ABAP, rated CVSS 9.9. It may cause memory corruption, data access, modification, and service disruption.
A temporary SICF workaround exists, but it disables some SAP GUI for HTML functions. SAP and Onapsis therefore recommend applying the ABAP Kernel patch.
SAP has also addressed CVE-2026-27690 in SAP Approuter and CVE-2026-44761 in SAP Commerce Cloud. In the latter case, verify whether a sample OAuth client with default credentials remains in production.
Why it matters: even without signs of active exploitation, these issues directly affect confidentiality, integrity, and availability.
Have you reviewed your SAP systems yet?
#SAP #cybersecurity #vulnerability #enterprise

