FeedVulnerabilitySAP fixes critical flaws in NetWeaver and Commerce Cloud...
VulnerabilityBleeping Computer
9.9CRITICAL

SAP fixes critical flaws in NetWeaver and Commerce Cloud

📅 9 June 2026 at 19:36 UTC📰 Bleeping ComputerView original source ↗
SAP fixes critical flaws in NetWeaver and Commerce Cloud

SAP has released fixes for 15 vulnerabilities as part of its June 2026 Security Patch package, including four critical-severity flaws affecting SAP NetWeaver and SAP Commerce Cloud. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

SAP has released fixes for 15 vulnerabilities, including four critical-severity flaws in NetWeaver and Commerce Cloud, which could allow attackers to bypass authentication, exploit memory corruption, or manipulate HTTP headers.

⚙️Technical Details
💥Impact Assessment
Severity: Critical
🛡️Recommended Actions
1Apply patches to SAP NetWeaver and Commerce Cloud as soon as possible
2Disable SAML authentication until the vulnerability is patched
3Monitor for suspicious activity in HTTP logs
📦Affected Products
Vmware Spring SecurityApache TomcatApache Tomcat NativeSAP NetWeaverSAP Commerce Cloud
🔐NVD Verified DataVERIFIED
CVE-2026-44748CVSS 9.9CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-347
CVE-2026-27671CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-121
CVE-2026-22732CVSS 9.1CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-425
Affected Products (CPE)
Vmware Spring Security
CVE-2026-40128CVSS 9CRITICAL
Attack Vector
NETWORK
Complexity
HIGH
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-35
CVE-2026-29145CVSS 9.1CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-287
Affected Products (CPE)
Apache TomcatApache Tomcat Native

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed