INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw

| 2026-07-14 18:17 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The SAP NetWeaver Application Server ABAP vulnerability has been identified as a critical flaw that could expose or modify data, with a CVSS score of 9.9. This out-of-bounds write flaw allows an authenticated attacker to leverage logical errors in memory management to cause unauthorized access, modification, or system unavailability. The vulnerability is currently being patched by SAP and its partners, including the National Vulnerability Database (NVD) which has added it to their Known Exploited Vulnerabilities catalog since November 2023.
Technical Mitigations AI-generated
* Disable ICF nodes with specific property: As a temporary workaround, customers should disable all ICF (Intrusion Countermeasures Framework) nodes with a specific property in transaction SICF. This will prevent an attacker from exploiting the vulnerability. * Update ABAP Kernel version: SAP recommends installing the patching ABAP Kernel version to address the memory corruption security issue (CVE-2026-44747). * Remove or replace default OAuth 2.0 client credentials: Customers should audit their production environments for the presence of the affected sample OAuth 2.0 client and remove it if present, or replace the hard-coded secret with a strong, unique value. * Monitor for exploitation attempts: Keep an eye on your system's logs and monitoring tools to detect any unauthorized access attempts using the vulnerable credentials. * Implement secure configuration practices: Ensure that all sample configurations scripts are properly secured by removing or replacing default settings, and use secure coding practices when developing new applications.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

No•••••.js
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-27690CVE-2026-27690 CVE-2026-44747CVE-2026-44747 CVE-2026-44761CVE-2026-44761
Target & Sectors
DACH DACH technologytechnology
Incident Timeline
‎November 2021
Threat actors used a SAP Patches CVSS 9.9 NetWeaver ABAP Flaw to target the company in November 2021.
general_metric 14  Jul
tactic Ransomware
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
‎fiscal year 2025
Threat actors exploited a SAP Patches CVSS 9.9 NetWeaver ABAP Flaw that could expose or modify data on affected servers in Germany and target companies with revenues exceeding €36 billion.
target_region Germany
financial €36 revenues
general_metric 99 year
general_metric 100 largest companies
‎June 2026
Threat actors exploited a SAP Patches CVSS 9.9 NetWeaver ABAP Flaw in the June 2026 Security Patch package to compromise multiple official SAP npm packages, aiming at stealing credentials from developers' systems.
general_metric 15 vulnerabilities
‎Jul 14, 2026
Threat actors exploited a CVSS 9.9 NetWeaver ABAP flaw in SAP Patches to gain unauthorized access and potentially expose or modify sensitive data on affected systems.
‎2026/07/14
Threat actors used default credentials to gain access tokens and read or modify data via certain APIs in the SAP Commerce Cloud enterprise e-commerce platform.
general_metric 14  Jul
tactic Ransomware
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
vulnerability CVE-2026-44761
‎2026/07/14
Threat actors used an HTTP Request Smuggling vulnerability in SAP Approuter to target the NetWeaver Application Server ABAP.
organisation SAP Patches
organisation Modify Data
organisation the NetWeaver Application
organisation Business Technology Platform
organisation SAP
organisation NetWeaver
organisation SAP NetWeaver Application
organisation Unauthenticated
organisation EDR
‎July 2026
SAP has rolled out updates to address multiple vulnerabilities, including a critical flaw in SAP NetWeaver Application Server ABAP that allows an authenticated attacker to leverage logical errors in memory management.
organisation SAP
organisation SAP NetWeaver Application
tactic T1584.004 - Server
general_metric 14  Jul
tactic Remote Code Execution
organisation DLL
organisation SQL
organisation AppRouter
general_metric 16 vulnerabilities
organisation CVE-2026-27690
infrastructure 9.1
organisation SAP GUI
organisation HTML
organisation Kernel
organisation CVE-2026
organisation the NIST National Vulnerability Database
organisation NVD
organisation SAP Approuter
organisation DoS
organisation SAP Commerce Cloud
organisation SAP Help Portal
victims 2.0 client
Tactical Metrics
Metrics
infrastructure
‎9.1
Software Version
Metrics
victims
2
Client
Metrics
financial
36,000,000,000
Revenues
Intelligence Sources