SAP released its June Security Patch Day updates to fix multiple vulnerabilities across products including SAP NetWeaver AS ABAP, ABAP Platform, SAP NetWeaver Application Server Java, SAP Commerce Cloud, SAP Data Hub, SAP S/4HANA, SAP Business Objects Business Intelligence Platform, and SAP Fiori launchpad. The issues could allow cross-site scripting, denial of service, email spoofing, sensitive information disclosure, privilege escalation, data manipulation, arbitrary code execution, and unauthorized access.
The most severe flaws include CVE-2026-44748, an XML Signature Wrapping weakness in SAML authentication affecting SAP NetWeaver AS ABAP and ABAP Platform with a CVSS 9.9, and CVE-2026-40128, a directory traversal vulnerability in the SAP NetWeaver Application Server Java Web Container rated CVSS 9.0. EG-FinCIRT said organizations should apply the patches as soon as testing is complete to reduce exposure across affected SAP environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
SAP released its June 2026 Security Patch Day updates to fix multiple vulnerabilities across products including SAP NetWeaver AS ABAP, SAP Commerce Cloud, SAP Data Hub, SAP NetWeaver Application Server Java, SAP S/4HANA, SAP Business Objects BI Platform, and SAP Fiori launchpad. The notice highlighted CVE-2026-44748 and CVE-2026-40128 among the patched issues and urged organizations to deploy the fixes after testing.
EG-FinCIRT published an Ivanti security update notice dated 02 June 2026. The provided reference does not include further event details in the content excerpt.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
egfincirt-wpn.azurewebsites.net
Open sourceegfincirt.org.eg
Open sourcezeropath.com
Open sourcezeropath.com
Open sourceegfincirt-wpn.azurewebsites.net
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.