SAP released 15 new security notes to fix vulnerabilities across major product lines, with four critical issues demanding immediate attention in SAP NetWeaver, SAP Commerce Cloud, and SAP Data Hub. The most severe flaw, CVE-2026-44748 (CVSS 9.9), is an XML signature wrapping weakness in SAML authentication for SAP NetWeaver AS ABAP and ABAP Platform that could let an authenticated attacker tamper with signed identity data, leading to unauthorized access and privilege escalation. SAP also patched CVE-2026-27671 (CVSS 9.8), an unauthenticated memory corruption bug in the ABAP kernel’s RFC handling that can be triggered with crafted RFC requests.
Other critical fixes include CVE-2026-40128, a directory traversal flaw in SAP NetWeaver AS Java Web Container, and CVE-2026-22732, a Spring Security issue affecting SAP Commerce Cloud and SAP Data Hub that could expose clients to connection hijacking. Additional patches addressed weaknesses in SAP S/4HANA, ODP Data Replication APIs, SAP Wily Introscope Enterprise Manager, SAP MDG, SAP Business Objects, and SAP Fiori launchpad, including SQL injection, reflected XSS, and Apache Log4j exposure. Canada’s Cyber Centre urged administrators to review SAP advisories, apply updates, and follow recommended mitigations across affected ABAP and Java environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft's June 2026 Patch Tuesday addressed 198 CVEs, including 32 critical and 166 important vulnerabilities, making it the largest Patch Tuesday release on record. The update included fixes for three zero-days disclosed before patches were available, as well as notable issues affecting BitLocker, HTTP.sys, Windows Collaborative Translation Framework, and Remote Desktop Client.
On June 9, 2026, the Canadian Centre for Cyber Security published advisory AV26-562 in response to SAP's June 2026 Security Patch Day. It urged administrators to review SAP's advisories and apply recommended mitigations and updates across affected SAP product families.
On June 9, 2026, SAP released its June 2026 Security Patch Day advisories, issuing 15 new security notes for vulnerabilities across multiple SAP products. The release included critical fixes for SAP NetWeaver AS ABAP, SAP Commerce Cloud, SAP Data Hub, and SAP NetWeaver AS Java components.
SAP received CVE-2026-40128 on June 9, 2026, describing a directory traversal vulnerability in the Web Container component of SAP NetWeaver Application Server Java. The flaw could be exploited through a malicious HTTP logon request to access or alter sensitive files.
SAP's CNA received CVE-2026-27671 on June 9, 2026, covering a critical memory corruption flaw in the SAP Kernel used by Application Server ABAP of SAP NetWeaver and ABAP Platform. The bug can be triggered by an unauthenticated crafted RFC request.
A new CVE entry for CVE-2026-44748 was received by SAP on June 9, 2026, describing an XML signature wrapping flaw in SAML authentication for SAP NetWeaver AS ABAP and ABAP Platform. The issue could allow tampered signed XML to be accepted, leading to unauthorized access and other impacts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcecyber.gc.ca
Open sourcesecuritybridge.com
Open sourcecybersecuritynews.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcebleepingcomputer.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.