# SAP Patches Four Critical Vulnerabilities Exposing Enterprise Systems to Identity Spoofing and Remote Exploitation
Enterprise software giant SAP released 15 new security notes on Tuesday, June 9, 2026, addressing critical flaws that could allow attackers to forge user identities, corrupt system memory, and bypass file access restrictions. Four of the patches resolve vulnerabilities with CVSS scores of 9.0 or higher—a rarity in enterprise patching cycles and a signal that defenders need to move quickly.
## The Threat
SAP's NetWeaver platform and ABAP infrastructure form the backbone of enterprise resource planning (ERP) systems across financial services, manufacturing, healthcare, and government. A vulnerability in these core systems doesn't just affect one application; it cascades through entire organizational IT ecosystems. This week's patch batch includes flaws that fundamentally undermine two of the most critical security assumptions in enterprise computing: that signed messages are authentic, and that unauthenticated users cannot trigger system crashes.
The most severe vulnerability, CVE-2026-44748 (CVSS 9.9), exploits a flaw in XML Signature Wrapping within SAML authentication. While the vulnerability requires the attacker to be authenticated with normal privileges, the impact is severe: an attacker can obtain a valid signed message from a legitimate user and modify it—injecting false identity information—before resubmitting it to the system. Because the XML structure remains intact and the signature validates, the compromised authentication service accepts the forged credentials as legitimate. This attack pattern, known as XML Signature Wrapping, has haunted enterprise authentication systems for over a decade, yet it continues to resurface in new implementations.
More dangerous still is CVE-2026-27671 (CVSS 9.8), a memory corruption flaw in the NetWeaver kernel's Remote Function Call (RFC) protocol handler. This vulnerability requires no authentication whatsoever. An attacker on the network can send crafted RFC requests that trigger improper memory management, potentially leading to arbitrary code execution or system denial-of-service. The RFC protocol is a foundational part of SAP's system-to-system communication, meaning vulnerable instances may be exposed if directly connected to untrusted networks or via compromised partner systems.
Two additional critical flaws round out the patch set: a directory traversal vulnerability in NetWeaver's Java web container (CVE-2026-40128) allowing unauthenticated attackers to manipulate file inclusion parameters, and a Spring Security configuration flaw (CVE-2026-22732) affecting Commerce Cloud deployments. Together, these vulnerabilities expose a troubling pattern: SAP's June 2026 patch cycle reveals that core validation and authentication mechanisms in foundational enterprise software have eroded.
## Severity and Impact
| CVE ID | CVSS Score | Vulnerability Type | Attack Vector | Authentication Required | Affected Product |
|--------|------------|-------------------|----------------|------------------------|-----------------|
| CVE-2026-44748 | 9.9 | XML Signature Wrapping | Network | Yes (Low Privilege) | NetWeaver AS ABAP, ABAP Platform |
| CVE-2026-27671 | 9.8 | Memory Corruption | Network | No | NetWeaver, ABAP Platform |
| CVE-2026-22732 | 9.1 | Improper HTTP Header Handling | Network | No | Spring Security Framework, Commerce Cloud, Data Hub |
| CVE-2026-40128 | 9.0 | Directory Traversal | Network | No | NetWeaver Application Server Java (Web Container) |
## Affected Products
SAP NetWeaver AS ABAP and ABAP Platform:
SAP Commerce Cloud and Data Hub:
Broader Ecosystem:
## Mitigations
Immediate Actions (within 72 hours):
Short-Term Hardening (1-2 weeks):
Long-Term Improvements:
## References
---
## HackWire Analysis
The convergence of four critical vulnerabilities in a single patch cycle signals a systemic problem in how enterprise software handles fundamental security operations. XML Signature Wrapping, memory corruption in protocol handlers, and directory traversal—these are not novel attack patterns. They are repeatedly rediscovered failures of validation and bounds-checking that suggest either insufficient security testing, pressure to ship features over correctness, or architectural shortcuts that trade security for performance.
What distinguishes this patch cycle is the *unauthenticated attack surface*. CVE-2026-27671 and CVE-2026-40128 require no credentials, meaning every SAP NetWeaver instance directly exposed to a network—whether intentionally or through misconfiguration—becomes an attack target. This matters because SAP infrastructure, by design, often sits at the center of organizational IT, processing financial transactions, supply chain data, and operational metrics. A memory corruption vulnerability in the RFC kernel is not a theoretical risk; it is a bridgehead for attackers to pivot deeper into enterprise systems.
Organizations that delayed patching from previous SAP cycles are now facing compounding risk. If you haven't updated since March 2026, you're carrying forward both old and new vulnerabilities simultaneously. The RFC memory corruption (CVE-2026-27671) in particular suggests that SAP's kernel validation has been compromised for some time and may be older than this patch cycle indicates.
For defenders, the actionable insight is this: treat SAP patch Tuesdays as security events comparable to Microsoft's Patch Tuesday. Block time to test and deploy. If your organization cannot patch NetWeaver within two weeks of release, you need to architect a remediation plan—either through network segmentation, failover systems, or acceleration of cloud migration. The risk here is not marginal.
— HackWire Editorial
## Related Coverage