# SAP Patches Four Critical Vulnerabilities Exposing Enterprise Systems to Identity Spoofing and Remote Exploitation


Enterprise software giant SAP released 15 new security notes on Tuesday, June 9, 2026, addressing critical flaws that could allow attackers to forge user identities, corrupt system memory, and bypass file access restrictions. Four of the patches resolve vulnerabilities with CVSS scores of 9.0 or higher—a rarity in enterprise patching cycles and a signal that defenders need to move quickly.


## The Threat


SAP's NetWeaver platform and ABAP infrastructure form the backbone of enterprise resource planning (ERP) systems across financial services, manufacturing, healthcare, and government. A vulnerability in these core systems doesn't just affect one application; it cascades through entire organizational IT ecosystems. This week's patch batch includes flaws that fundamentally undermine two of the most critical security assumptions in enterprise computing: that signed messages are authentic, and that unauthenticated users cannot trigger system crashes.


The most severe vulnerability, CVE-2026-44748 (CVSS 9.9), exploits a flaw in XML Signature Wrapping within SAML authentication. While the vulnerability requires the attacker to be authenticated with normal privileges, the impact is severe: an attacker can obtain a valid signed message from a legitimate user and modify it—injecting false identity information—before resubmitting it to the system. Because the XML structure remains intact and the signature validates, the compromised authentication service accepts the forged credentials as legitimate. This attack pattern, known as XML Signature Wrapping, has haunted enterprise authentication systems for over a decade, yet it continues to resurface in new implementations.


More dangerous still is CVE-2026-27671 (CVSS 9.8), a memory corruption flaw in the NetWeaver kernel's Remote Function Call (RFC) protocol handler. This vulnerability requires no authentication whatsoever. An attacker on the network can send crafted RFC requests that trigger improper memory management, potentially leading to arbitrary code execution or system denial-of-service. The RFC protocol is a foundational part of SAP's system-to-system communication, meaning vulnerable instances may be exposed if directly connected to untrusted networks or via compromised partner systems.


Two additional critical flaws round out the patch set: a directory traversal vulnerability in NetWeaver's Java web container (CVE-2026-40128) allowing unauthenticated attackers to manipulate file inclusion parameters, and a Spring Security configuration flaw (CVE-2026-22732) affecting Commerce Cloud deployments. Together, these vulnerabilities expose a troubling pattern: SAP's June 2026 patch cycle reveals that core validation and authentication mechanisms in foundational enterprise software have eroded.


## Severity and Impact


| CVE ID | CVSS Score | Vulnerability Type | Attack Vector | Authentication Required | Affected Product |

|--------|------------|-------------------|----------------|------------------------|-----------------|

| CVE-2026-44748 | 9.9 | XML Signature Wrapping | Network | Yes (Low Privilege) | NetWeaver AS ABAP, ABAP Platform |

| CVE-2026-27671 | 9.8 | Memory Corruption | Network | No | NetWeaver, ABAP Platform |

| CVE-2026-22732 | 9.1 | Improper HTTP Header Handling | Network | No | Spring Security Framework, Commerce Cloud, Data Hub |

| CVE-2026-40128 | 9.0 | Directory Traversal | Network | No | NetWeaver Application Server Java (Web Container) |


## Affected Products


SAP NetWeaver AS ABAP and ABAP Platform:

  • All supported versions are affected by CVE-2026-44748, CVE-2026-27671, and the missing authorization checks
  • NetWeaver Application Server Java (Web Container) affected by CVE-2026-40128

  • SAP Commerce Cloud and Data Hub:

  • CVE-2026-22732 impacts all applications relying on the Spring Security framework
  • Commerce Cloud also affected by Apache Tomcat vulnerabilities patched in this cycle

  • Broader Ecosystem:

  • Any custom or third-party application deployed on SAP NetWeaver infrastructure is potentially at risk
  • Organizations using RFC protocol integrations with SAP systems (partner connections, system-to-system automation)

  • ## Mitigations


    Immediate Actions (within 72 hours):

  • Apply the official SAP patches released June 9, 2026 to all NetWeaver AS ABAP, ABAP Platform, and Commerce Cloud instances
  • Test patches thoroughly in non-production environments before deployment, given the criticality of these systems
  • If patching cannot be deployed immediately, consider temporarily disabling SAML authentication on NetWeaver AS ABAP as a temporary stopgap (Onapsis confirms this mitigates CVE-2026-44748), though this will significantly degrade user experience
  • Disable or restrict direct network access to RFC ports (typically TCP 3200-3299) to unauthenticated networks

  • Short-Term Hardening (1-2 weeks):

  • Segment SAP infrastructure from general corporate networks using network access controls and firewalls
  • Implement network intrusion detection (IDS/IPS) rules tuned to detect malformed RFC protocol requests
  • Audit authentication logs for evidence of identity tampering or unusual SAML token modifications
  • Review all users with administrative or elevated privileges on NetWeaver systems, as these accounts pose elevated risk under CVE-2026-44748

  • Long-Term Improvements:

  • Establish a formal SAP patch management process with defined SLAs for critical vulnerability deployment (recommend within 2 weeks)
  • Conduct a security assessment of custom applications and integrations running on NetWeaver infrastructure
  • Consider moving to SAP's cloud-hosted ABAP Platform to reduce patching overhead and ensure timely security updates
  • Implement defense-in-depth around SAML authentication using multi-factor authentication and advanced anomaly detection

  • ## References


  • [SAP Security Notes - June 2026 Patch Cycle](https://support.sap.com/en/my-support/security-notes-and-updates.html)
  • [Onapsis Security Advisory - CVE-2026-44748](https://www.onapsis.com/)
  • [NIST NVD - CVE-2026-22732](https://nvd.nist.gov/)
  • [SecurityWeek Original Reporting](https://www.securityweek.com/)

  • ---


    ## HackWire Analysis


    The convergence of four critical vulnerabilities in a single patch cycle signals a systemic problem in how enterprise software handles fundamental security operations. XML Signature Wrapping, memory corruption in protocol handlers, and directory traversal—these are not novel attack patterns. They are repeatedly rediscovered failures of validation and bounds-checking that suggest either insufficient security testing, pressure to ship features over correctness, or architectural shortcuts that trade security for performance.


    What distinguishes this patch cycle is the *unauthenticated attack surface*. CVE-2026-27671 and CVE-2026-40128 require no credentials, meaning every SAP NetWeaver instance directly exposed to a network—whether intentionally or through misconfiguration—becomes an attack target. This matters because SAP infrastructure, by design, often sits at the center of organizational IT, processing financial transactions, supply chain data, and operational metrics. A memory corruption vulnerability in the RFC kernel is not a theoretical risk; it is a bridgehead for attackers to pivot deeper into enterprise systems.


    Organizations that delayed patching from previous SAP cycles are now facing compounding risk. If you haven't updated since March 2026, you're carrying forward both old and new vulnerabilities simultaneously. The RFC memory corruption (CVE-2026-27671) in particular suggests that SAP's kernel validation has been compromised for some time and may be older than this patch cycle indicates.


    For defenders, the actionable insight is this: treat SAP patch Tuesdays as security events comparable to Microsoft's Patch Tuesday. Block time to test and deploy. If your organization cannot patch NetWeaver within two weeks of release, you need to architect a remediation plan—either through network segmentation, failover systems, or acceleration of cloud migration. The risk here is not marginal.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)